Add a pull_request-triggered caller that invokes the org-level callable-dependency-review workflow to scan dependency changes and fail on high-severity advisories.