Address GitHub code scanning alerts with OIDC SSRF guards, confined path helpers, safer client routing, branding sanitization, upload rate limits, and CodeQL config exclusions for dev-only and protocol-intentional hashes.
Keep apply-i18n-audit and regional patch data for low-cost locale maintenance without shipping dev scripts to production consoles. Add collect-gap-keys to regenerate gap-fill input from i18n-check.