Backend job had static checks (ruff/mypy) and a dependency-vulnerability gate but no secret scan; frontend had a dependency audit but no secret scan either. Adds trufflehog once, on the backend job's full checkout, covering the whole repository - the last gap for this repo to count as fully-authored.