New parallel lint job running Staticcheck (all checks) pinned to
2026.2.1 — the version the codebase was validated against — with the
action pinned by commit SHA like the others. Two findings it surfaced
on first run are already fixed in the parent commit.
Action references by tag (checkout@v4, setup-go@v5,
govulncheck-action@v1) execute whatever a retargeted tag points at,
so a compromised tag would run with contents:read on this repo. Pin
each to the commit SHA its tag resolves to today, and cancel
superseded runs on the same ref.