Skip to main content

Defending software build pipelines from malicious attack

Compromise of your software build pipeline can have wide-reaching impact; here's how to tackle the problem.

This content was last reviewed on 05/03/2025

Security for software developers is something the NCSC is often asked about, but one area often overlooked is the software build process. This blog explains why your build pipeline is one of the foundations of your system security, and why you should give it particular attention. See our guidance for the other security aspects of build process security, like code reviews and secrets management.







Written by

Jamie H Principal Security Researcher