new --audit option for sbom output

query OSV API for vulnerabilities and (just) print a summary
2 jobs for feat/cyclonedx-wip
in 0 seconds, using 0 compute credits, and was queued for 0 seconds
latest