Goals are:
- automating myself/give an easy way to the whole dev team to triage security issues in our dependencies
- have a global view of the current state of dependencies so we can answer "What known vulnerabilities there is in our dependency tree"
As a first step only PHP/Packagist, JS/npm, Rust/cargo and go dependencies will be covered.