ship(P10): security scanning merged into v0.2 milestone
Phase 10 (P03) ships: - .coreci.yml validate pipeline: gosec, govulncheck (offline mode), gitleaks in order; gitleaks baseline suppresses the v0.1 historical .env leak - scripts/security_scan.sh wrapper for local dev - .gitleaks.toml with cert PEM allowlist (REQ-039) - .gitleaks-baseline.json (REQ-029) - .golangci.yml unified config (REQ-040) with gosec severity=high so G101 (hardcoded credentials) is a build-breaker - .githooks/pre-commit gitleaks gate (skip if not installed) - docs/security-scanning.md operator doc - Makefile test-race + security-scan targets (REQ-031) - scripts/release.sh now passes --repo coreci/orca to tea (P01 audit fix; was missing in v0.2.1) Coverage: - REQ-014 gosec+govulncheck in CI - REQ-027 govulncheck offline mode - REQ-029 gitleaks baseline for pre-existing .env - REQ-031 go test -race in CI - REQ-039 .gitleaks.toml with cert PEM allowlist - REQ-040 .golangci.yml unified config ---ci--- project: orca phase: 10 milestone: v0.2 status: ship version: v0.2.3 requirements: covered: [REQ-014, REQ-027, REQ-029, REQ-031, REQ-039, REQ-040] partial: [] ---/ci---
This commit is contained in: