{
  "tool": "semgrep",
  "image": "semgrep/semgrep@sha256:06938c1f365d3f67b8cedd8bc117607ae64253f88a0e768e9da9408548927dd6",
  "date": "2026-07-08",
  "target": "repository tree (git-tracked, 18 files incl. test project)",
  "rulesets": [
    "p/csharp",
    "p/security-audit",
    "p/secrets",
    "p/owasp-top-ten"
  ],
  "rules_run": 104,
  "files_scanned": 18,
  "findings": 0,
  "results": [],
  "note": "0 findings across app + tests + CI workflows. Re-audit pass (org-migration prep): CI moved from ubuntu-latest to self-hosted [self-hosted, home-ci, windows], and the Semgrep image was re-pinned from the mutable `latest` tag to a content digest (flagged MEDIUM by a Codex supply-chain review) so the scanner itself can't silently change. Re-runs in CI (.github/workflows/security.yml) on every push; SARIF uploaded as a build artifact."
}
