security-catalog 에서 포팅: build-hardened-image.sh, patch-catalog-tag.py, build-image.yml(REGISTRY_HOST=docker.io/paasup). images/ 는 아직 비어있다 — 베이스 OS 정책 미결 등은 .claude/image-authoring.md, MEMORY.md 참고.
security-catalog 에서 포팅: 고유 CVE 단위 집계, max(벤더,NVD) 실효 등급, 승인 예외(doc/cve-exceptions.json) 처리. 워크플로 연결은 다음 커밋에서.
doc/scripts/ -> scripts/pipeline/ (security-catalog 의 최상위 scripts/ 관례 채택). 스크립트 로직은 변경 없음 (상대경로 깊이 동일).