Review what a change or pull request introduces into the dependency tree - new packages, version bumps, typosquats, install scripts, vulnerabilities - using postmortem diff plus mlab.sh enrichment. Use when reviewing a PR that touches a lockfile, comparing two branches' dependencies, or gating dependency changes in CI.