SAST, DAST, dependency vulnerability scanning, image scanning, SBOM, license compliance, and CI/CD security gate design in a DevSecOps workflow.