Generate a CycloneDX SBOM locally with postmortem and push it through mlab.sh vulnerability scanning - for projects or container images where no single lockfile can be pasted. Use when the user asks for an SBOM, needs vuln scanning of a container image or a multi-ecosystem repo, or when sbom-audit lacks a usable lockfile.