Nothing in CI guarded against known vulnerabilities in the Go dependency tree. Add a vulncheck job that runs govulncheck over the backend module on every backend change. The version is pinned rather than tracking latest for reproducible runs. Current tree scans clean.