CI/CD: every stage carries a trust boundary
Building code and authorizing production are different decisions.
Security in development, pipelines, dependencies and vulnerability management.
Building code and authorizing production are different decisions.
Inventory must connect to running software.
Pipeline dependencies deserve code-level scrutiny.
Repositories represent environments only when differences are reconciled.
Central storage does not replace rehearsed revocation.
Diff size does not measure security impact.
Rebuilding at the last step can change the trust unit.
Component severity is an input, not the whole context.
Thiago Lima Soneti da Silva (Thiago Silva) — Cyber Architect and technical lead at Lima e Silva Tecnologia.