a4f8f91e50
The scan is detection-only and its findings are the repo-wide baseline of CVEs in pinned dependencies — identical for every PR, unrelated to any PR's diff. Reporting that baseline in each PR's review comment read as "this PR has 76 vulnerabilities" to contributors, and the SARIF upload tripped GitHub's per-installation API rate limit during merge trains. The scheduled weekly run (plus workflow_dispatch) keeps feeding the Security tab; the per-PR workflow_call, the review_status wrapper job, and the orchestrator's now-unneeded SARIF permissions are removed.