- add SCA & SAST - use wildcards to reference jars' locations - a single static scan will be triggered - use sandbox based on git branch - use maven plugin for source clear scans - filter logs