Security reports for Forge apps: the clean scan that isn't (2026)
Key takeaways
"It's sandboxed, so SAST/SCA don't apply" is wrong: running them found a reachable HIGH in my own app.
When a vendor abandons npm, OSV-based scanners (Trivy, Grype, Dependabot, Snyk) fl