1. Snapshots to be published for anything merged to develop 2. Install build for merges to main 3. Manual action created to publish releases (can only run on release/ branches) 4. Add dependency scanning (Depend-a-bot / Lift / Other) 5. Add static security scanning for code