Vet a new or changed third-party dependency for license, provenance, and supply-chain risk before any install runs.