- Scan the repository filesystem for CRITICAL and HIGH vulnerabilities and upload SARIF results to the GitHub Security tab
- Build the Docker image and scan it, gating the build on CRITICAL findings only
- Run quarterly on a schedule, on manual dispatch, and on pushes and pull requests to the default branch
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>