# feature-security-operational-baseline D5 — deny-by-default public path snapshot. # SSOT: ca-skeleton.security.public-paths default in app-bootstrap/src/main/resources/config/security.yml # -> SecurityConfig permitAll(); anyRequest authenticated. An operator's own SECURITY_PUBLIC_PATHS # overrides it at run time and is outside this snapshot. # Update only after review with: ./gradlew updatePublicPathSnapshot -PapprovePublicPathChange /v1/healthcheck