Audit modules, verify checksums and provenance, generate software bills of materials, and respond to vulnerability reports with Go security tools. Harden CI against compromised dependencies, build scripts, credentials, and artifact tampering.