Artifact Registry: staged AppSec code reviews (closed beta)
## :dart: Why
The [closed-beta roadmap](https://gitlab.com/gitlab-org/ops/artifact-registry/-/blob/main/docs/roadmap/closed-beta.md) lists **AppSec review/approval** as a readiness gate. This epic is to track that.
Agreement with AppSec: MRs are reviewed continuously during development through the AppSec AI review flow; the human review and manual testing happen **in stages, one chunk of the application at a time as each completes**, avoiding a single big-bang review at the end. This mirrors the staged per-format model of the [DB review](https://gitlab.com/groups/gitlab-org/-/work_items/22162).
## :compass: How
One child issue per chunk: scope, code paths, ties to the [threat model](https://gitlab.com/gitlab-com/gl-security/product-security/appsec/threat-models/-/merge_requests/78) (T-01..T-10), and manual test approach. The threat-model follow-up issues (gitlab-org/ops/artifact-registry#79 through gitlab-org/ops/artifact-registry#88) are attached to this epic.
Order: Container/OCI hosted (ready now), then npm and Maven hosted as they complete, then the remote/virtual formats (one issue per format; the S13 foundation is reviewed with the first to complete), then the management API, then the composition-root encryption wiring (gitlab-org/ops/artifact-registry#513, covering root-key handling, the secrets path, and zeroization at the boundary).
epic