Code review does not protect a compromised runner

Reviewing code carefully is worth nothing if the machine that builds it has been tampered with.

The runner sees the source, holds the secrets, produces the artefact and can modify any of them. Every review in the world happens upstream of that. This is why build infrastructure deserves the same scrutiny as the code, and why it usually receives far less.

More on CI/CD security