This issue tracks the rollout of application security in CI, including: * [x] Dependabot Alerts * [x] Dependabot Security updates * [x] Dependabot Version updates * [x] CodeQL * [x] secret scanning and push protection * [x] private vulnerability reporting * [x] dependency review * [x] OpenSSF scorecard and best practices (badges in README) * [x] release artifact signing * [x] release SBOMs * [x] coverage (badge in README) * [x] code linters