The supply-chain check at work. The interesting failures are never the direct
dependencies — they are four levels down a lockfile, in a package nobody chose, which is
why the scan has to run on the lockfile and not the package.json. Here the equivalent is
pnpm's own audit and the lockfile normalizer in the pre-commit hook.