## Summary
This PR integrates security-focused checks into the existing quality gates and aligns local workflows with CI/CD execution.
## What changed
- Added Bandit to pre-commit backend checks.
- Integrated eslint-plugin-security into the existing frontend ESLint setup used by pre-commit.
- Added dedicated audit tasks:
- backend audit via pip-audit
- frontend audit via yarn npm audit
- Updated CI/CD workflow to include and gate on frontend/backend audit jobs.
- Switched backend vulnerability scanning from Safety to pip-audit to avoid interactive/auth requirements in CI.
- Updated backend dependency set and lockfile to resolve test dependency conflicts and keep the environment solvable.
- Marked backend integration API tests with the integration marker so marker-based unit/integration separation works consistently.
## Validation
- Pre-commit hooks run and pass after formatting/autofixes.
- Branch commit created successfully after hook-driven file updates.
- Branch pushed to remote and tracking is configured.
## Notes
- pip-audit now executes from backend context (for example via uv --directory backend run ...), matching project layout.
- Remaining reported vulnerabilities depend on upstream package fix availability/constraints and may require follow-up once publishable fix versions are consumable.
## Follow-ups (optional)
- Add a curated pip-audit ignore policy for non-actionable/transient advisories with rationale.
- Open a focused follow-up PR for remaining dependency advisories once upstream fixes are practically installable.
Co-authored-by: copilotcoder <copilotcoder@darkhelm.org>
Reviewed-on: #74