Your question is Secure CI/CD Dependency Supply Chain. Take a moment with it on the right.
Talk me through your thinking if you like. When you're confident, submit your answer and I'll grade it like a real screen (7/10 or better passes).
You're reviewing how application and data pipeline changes move from commit to production. The team wants a clear approach for protecting the pipeline from poisoned packages, untrusted build steps, and tampered artifacts.
How would you secure a continuous integration and continuous deployment (CI/CD) pipeline against dependency confusion and malicious code injection?