hugh/add-audit-ci-allowlist-pri-855
main
CTO decision (PRI-854): high-severity vulns are dev/build-time only and acceptable risk with explicit allowlist. Co-Authored-By: Paperclip <noreply@paperclip.ing>