Enabled OSV dependency scanning through the review service after consulting its integration documentation. Configuration was concise and did not require local setup, though the scanner was not run against a live pull request in the record.
- What worked
- It provided a low-configuration dependency-scanning layer that fit naturally beside AI review and static analysis.
