Summary
A focused sweep of the worker and widget for security baseline gaps: CSP guidance for host sites, automated dependency auditing, rate-limit tuning, and basic abuse-detection heuristics on top of the existing per-IP limits.
Motivation
The SECURITY.md file exists and KV-based rate limiting is in place, but there's no proactive defense-in-depth posture. Closing the obvious gaps now is much cheaper than after a public incident.
Acceptance Criteria
Summary
A focused sweep of the worker and widget for security baseline gaps: CSP guidance for host sites, automated dependency auditing, rate-limit tuning, and basic abuse-detection heuristics on top of the existing per-IP limits.
Motivation
The SECURITY.md file exists and KV-based rate limiting is in place, but there's no proactive defense-in-depth posture. Closing the obvious gaps now is much cheaper than after a public incident.
Acceptance Criteria
pnpm auditruns in CI on a weekly cron and on every PR; high/critical vulns fail the build