Active signal DevSecOps

Headline

GitHub Actions hardens workflows and reduces classic `pwn request` paths.

Summary

GitHub moved two relevant controls for Actions: `actions/checkout` v7 now blocks insecure patterns in `pull_request_target` by default, and it also launched centralized policies to define who can trigger workflows and with which events. The combined signal is clear: CI/CD remains a critical supply-chain surface.