- Runs on every push and PR
- Tests all microservices
- Checks code quality
- Node.js and Python testing
- Builds Docker images
- Scans for vulnerabilities with Trivy
- Uploads security findings to GitHub Security
- Advanced security analysis
- Runs weekly and on every PR
- JavaScript and Python scanning
- Reviews dependencies on PRs
- Checks for known vulnerabilities
- Comments findings directly on PRs
- Automatically labels PRs based on changed files
- Helps organize and categorize changes