We need to decide on whether osv-scanner is able to effectively scan all the wikimedia repos in terms of the underlying language/application framework coverage.
Also decide what is a suitable configuration or policy for osv-scanner. For example do we find there's a certain level of severity of CVE or type of finding that is a high priority vs. some that are more like false positives or low severity issues.
Recommendation out of this would be how to run osv-scanner for USD and how to filter the results to identify higher priority findings.