What I check: GitHub Actions security (breakage from GitHub's 2026 pull_request_target changes, script injection in run steps, workflows that never limit their token, third-party actions pinned to a tag); pinned dependencies with published advisories in the OSV database (Python requirements, npm lockfiles); committed secrets, reported by file, line and kind, never the value; Python bugs that lint can prove, such as undefined names; and hygiene: tests, CI, license, security policy, dependency updates.