Secure CI/CD agent: action pinning, OIDC auth, least-privilege tokens, reusable workflows.