Build Security Group
The Build Security group owns SLSA, malicious package detection, and hardened build pipelines.
Mission
Own SLSA conformance, malicious package detection, and hardened build pipelines.
Team
| Role | Person |
|---|---|
| Engineering Manager | Mark Mishaev (@mmishaev, interim) |
| Tech Lead | To be hired |
The group is being staffed. Current membership is sourced from Workday and published on the product categories page.
Labels
| Scope | Label |
|---|---|
| Stage | devops::security platform |
| Group | group::build security |
Slack
The group Slack channel rename is in progress, tracked in Sec reorg issue 2.
History
This group was created in the FY27 Sec reorg. It has no predecessor group and inherits no label history, so its metrics start at the reorg cutover.
This page is a stub. Contributions from the group are welcome, see how to update the handbook.
Last modified August 13, 2026: Sec FY27 reorg (1/5): add stage pages and new team stubs (
8e3a4296)
