tools scan.sh — runs govulncheck (required to pass) and optional grype on the repo. For full image scan use make docker-scan from the repository root.