fix(security): enforce SSRF-safe outbound HTTP master
Centralize attacker-influenced egress behind a DNS-rebinding-resistant transport and fail closed on non-global destinations. This closes gaps across OAuth discovery, identity resolution, PDS calls, Jetstream fetches, aggregator registration, image and blob retrieval, profile backfill, rematerialization, and link unfurling. Changes: - validate DNS answers and socket destinations against one address policy - guard all Indigo OAuth clients and enforce redirect, timeout, and body limits - block local-use NAT64 and other non-global special-purpose ranges - keep private-host access behind explicit development-only wiring - add guard tests and a hard CI audit for unguarded client construction - publish stable SSRF and vulnerability-reporting documentation - refresh vulnerable dependencies and supported container toolchains Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>