Branch protection does not protect every release path
Guarding the main branch does nothing if things can ship from somewhere else.
Tags, release branches, manual deploys, direct pushes by automation, hotfix routes created during an incident and never removed. The question is not whether the branch is protected but whether every path to production passes through the control, and that map is usually longer than expected.
More on CI/CD security
- A deployment pipeline is a privileged production pathIt goes straight over the gate
- Code review does not protect a compromised runnerNobody looked inside the machine
- Forked code should not automatically receive secretsThe belt does not ask who sent it
- Deployment credentials should match deployment scopeOne bolt across all three
- Build logs can become secret leaksThe log is a page, and people read pages
- Self-hosted runners inherit local trustYou gave the job a desk indoors
