Protect source code, dependencies, build systems, artifact registries, and deployments from tampering. Apply software bills of materials, signing, provenance, vulnerability management, and controlled promotion.