* ci: add osv-scanner lockfile scan workflow
Daily scheduled scan plus a pull_request scan scoped to uv.lock and the
dashboard package-lock.json. The osv-scanner v2.3.8 binary is fetched by
full release URL and verified against its official SHA-256 before use;
the job needs no credentials and runs with contents: read only.
osv-scanner.toml carries the single suppression for the diskcache
advisory, which has no fixed release published
* ci: temporary push trigger for runtime verification (will be dropped)
* ci: harden osv-scan per review (RUNNER_TEMP, job-scoped permissions, suppression expiry)
* ci: drop temporary push trigger after runtime verification
* ci: suppress aiohttp advisories while vcrpy blocks the 3.14 bump
Time-boxed like the diskcache entry: ignoreUntil forces a dated
re-triage if no vcrpy release has shipped by then