```Code Scanning (CodeQL)``` -> Scan GitHub repo for vulns ```Secret scanning (free)``` -> Auto-detect leaked tokens ```Branch protection rules``` -> Enforce checks before merge