Location
.github/workflows/
Problem
No confirmed automated vulnerability scanning (npm audit, Snyk, or GitHub's native scanning) blocks merges when a new high-severity dependency vulnerability is introduced, for a service handling financial operations this matters more than average.
Acceptance Criteria
Location
.github/workflows/
Problem
No confirmed automated vulnerability scanning (npm audit, Snyk, or GitHub's native scanning) blocks merges when a new high-severity dependency vulnerability is introduced, for a service handling financial operations this matters more than average.
Acceptance Criteria