Platform · 2026-08-21

Continuous security scanning and release gates

Dependency, git-history secret, repository, DAST, image and license checks now block unsafe releases.

  1. 1

    Unexcepted Critical or High findings block release. Medium findings need an owner, due date and retest evidence.

  2. 2

    DAST is limited to localhost, private networks or an explicitly authorised staging origin.

  3. 3

    Scanner images are pinned by digest and GitHub Actions by full SHA.

  4. 4

    All nine release images must be scanned before production promotion.