The problem was never that Maven projects could not run security tools.

They could.

A pipeline can run tests, Dependency-Check, CycloneDX, and SonarQube with a few commands. A pom.xml can hold plugin blocks. A team can copy a working configuration from one service to another and call it a standard.

For a while, that works.

Then the small...