OWASP's new dependency scanner gives developers actionable fixes. But supply chain attacks aren’t yet CVEs.