Your question is Secure CI/CD Pipeline Design. Take a moment with it on the right.
Talk me through your thinking if you like. When you're confident, submit your answer and I'll grade it like a real screen (7/10 or better passes).
You're reviewing how software changes move from commit to deployment and want the pipeline itself to enforce security standards. The goal is to reduce risk early, not rely only on manual review or production controls.
Explain how you would implement security best practices within a CI/CD pipeline.