Add a pre-commit hook running gosec (pinned to the same version as CI, currently v2.26.1) so security findings surface at commit time instead of first failing in the Security Scanning CI job. Requirements: pinned version (never @latest, per feedback_ci_tool_version_pin); scan only the packages containing changed .go files (fast); respect the multi-module layout (root, pkg, providers/aws|azure|gcp, ci_cd_sanity_tests) by running gosec within the module owning each changed package; same flags as CI so local and CI verdicts agree; suppressions must use the #nosec form (see feedback_gosec_nosec_not_nolint). Complements #1363 (multi-module CI scan).
Add a pre-commit hook running gosec (pinned to the same version as CI, currently v2.26.1) so security findings surface at commit time instead of first failing in the Security Scanning CI job. Requirements: pinned version (never @latest, per feedback_ci_tool_version_pin); scan only the packages containing changed .go files (fast); respect the multi-module layout (root, pkg, providers/aws|azure|gcp, ci_cd_sanity_tests) by running gosec within the module owning each changed package; same flags as CI so local and CI verdicts agree; suppressions must use the #nosec form (see feedback_gosec_nosec_not_nolint). Complements #1363 (multi-module CI scan).