Fixes case-sensitivity regression where prohibited paths like
'.VERITAS-KANBAN/security.json' would not be caught on Linux CI,
even though they alias protected paths on case-insensitive systems.
Changes:
- Normalize candidate paths to lowercase in findSecurityArtifactViolations()
- Add comprehensive test file (security-artifacts-guard.test.ts) with:
* Unit tests for path normalization and matching
* Mixed-case variant detection
* NUL-delimited Git output handling
* Integration tests with isolated temporary Git repositories
* Edge cases: spaces, nested paths, untracked files
* Diagnostic message validation
Security verification:
- All security-related tests pass
- Auth middleware tests pass
- Typecheck passes
- Lint budget at 600 (limit)
- Guard invocation verified against live repository
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>