spotless https://github.com/diffplug/spotless/tree/main/plugin-gradle
added 0 dependency executable with git-lfs in root folder will take care of providing the detect-secrets executable
https://cz-git.qbb.sh/guide/ https://commitlint.js.org/
alternatives: https://commitizen.github.io/cz-cli/ https://github.com/commitizen/cz-cli https://pre-commit.com/ (python)
built in dependabot code-scanning security (open-source, paid)
apps renovate github-advanced-security (paid, includes codeQL and others) semgrep gitguardian snyk sentry (allows to track errors and link them to commit authors) sonarcloud
utilities stale: auto-close issues and PRs https://github.com/actions/stale greetings: welcome new contributors
possibly: super-linter
allows blocking pushing tags from others
dev and main branches