Building a security-conscious CI/CD pipeline