Build ErsatzTV Image / Docs update reminder (pull_request) Successful in 9s
Build ErsatzTV Image / decisions.md append-only (pull_request) Successful in 10s
Build ErsatzTV Image / Formatting (changed .cs conform to .editorconfig) (pull_request) Successful in 15s
Build ErsatzTV Image / API docs in sync (OpenAPI + endpoint index) (pull_request) Successful in 15s
Build ErsatzTV Image / Build & test (.NET) (pull_request) Successful in 10m1s
Build ErsatzTV Image / EF migration integrity (SQLite + MySql) (pull_request) Successful in 10m55s
Build ErsatzTV Image / Build & push image (amd64) (pull_request) Has been skipped
scripts/security-scan.sh: boots a THROWAWAY container from the image under test (fresh config volume; never the deployed prod/test container — the active scan attacks write endpoints), reads its machine key, and runs an authenticated OWASP ZAP api-scan that imports /openapi/v1.json (all 160 /api/v1 ops) and injects X-Api-Key on every request via a replacer rule so it reaches the [RequiresAuthentication] + RequireKeyForReads surface — then a semgrep SAST cross-check. Wrapped in `timeout` because zap-api-scan can hang in post-scan cleanup after the report is already written. docs/ci-cd.md: new 'Security scanning' section (out-of-ecosystem black-box gate, run on the docker host per-release like migration-smoke, not a per-PR CI job) + the Microsoft.OpenApi 2.7.5 pin note in dependency management. refs #314 #197 Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>