A few things it does: - Auto-fix common misconfigurations - Hardening profiles for typical deployment patterns - SARIF output so it drops right into GitHub Code Scanning or your CI/CD pipeline
Would love feedback — especially on what checks or hardening rules you'd want to see next.