Add vulnerability scanning when we cut a release so that release attestations include scan results and are evaluated by the appropriate policies.