- gitleaks (via docker cp, dockerignore-agnostic — this repo's own .dockerignore excludes .git, which a build-context COPY would have missed) and hadolint scan every push/PR - scheduled Trivy critical failures now attempt an apk upgrade rebuild and open a PR if it clears the finding, instead of just failing red - no ruff/pytest-cov here (shell project, already has shellcheck/bats)