Your question is Secure DevOps Pipeline Design. Take a moment with it on the right.
Talk me through your thinking if you like. When you're confident, submit your answer and I'll grade it like a real screen (7/10 or better passes).
You're reviewing how code moves from commit to deployment and want to build security into the pipeline instead of treating it as a final check. You need a practical approach that covers source control, build steps, secrets, artifact handling, and deployment controls.
How do you ensure security in a DevOps pipeline?