Focus 1
Secrets
Keep secrets out of repositories, prompts, CI logs, and generated artifacts.
Supply chain controls reduce exposure from dependencies, secrets, CI/CD permissions, and build provenance.
Focus 1
Keep secrets out of repositories, prompts, CI logs, and generated artifacts.
Focus 2
Use lockfiles, update policies, provenance checks, and security advisory monitoring.
Focus 3
Use least-privilege tokens and separate deploy rights from test rights.
Focus 4
Generate and retain a software bill of materials for deployable releases.