Artifact security governance: a scan loop from build output to repo ingest
Design the scan, gate, and traceability loop from build artifacts to repository ingest, and clarify division of labor with source-side scanning. Draw the build→scan→ingest-block path so known-risk artifacts stop spreading.