Security / CI hardening (SonarCloud)
- Close Sonar SECURITY findings PG-01…PG-08: publish input-injection hardening, e2e secret-via-env + sha256 example hash, job-scoped permissions (ci/e2e), Scorecard permissions (read-only top-level, job-scoped writes for publish), HTTPS curl pins,
version_diff.pypath bounding, DockerfileCOPYfor local artifacts - Meta-tests under
hack/test/sonar_pg_*guard the patterns
Documentation
- Keep press Bildmarke; remove logo candidates (BRAND-2)
- OpenSpec:
sonar-security-remediation-2026-07
Install: xpkg.upbound.io/platformrelay/provider-gridscale:v0.2.2
GHCR: ghcr.io/platformrelay/provider-gridscale:v0.2.2