Security reports for Forge apps: the clean scan that isn't (2026)
Key takeaways "It's sandboxed, so SAST/SCA don't apply" is wrong: running them found a reachable HIGH in my own app. When a vendor abandons npm, OSV-based scanners (Trivy, Grype, Dependabot, Snyk) fl
Sep 19, 202612 min read


