As a dev, I want PRs to be scanned for security vulnerabilities before being approved so that I can be reasonably sure I'm approving secure code