- Retained security improvements from master (token detection, cache prep, safe directory) - Applied security hardening by pinning actions/checkout@v4 to commit SHA 11bd71901bbe5b1630ceea73d27597364c9af683 - Added persist-credentials: false to checkout step to prevent credential exposure