Fail-closed npm and PyPI vulnerability checks in n8n

A dependency scan is only useful when it answers two different questions:

Did the public vulnerability sources report a finding for the exact version

I run?

Did every required source answer successfully?