security-catalog 에서 포팅: 고유 CVE 단위 집계, max(벤더,NVD) 실효 등급, 승인 예외(doc/cve-exceptions.json) 처리. 워크플로 연결은 다음 커밋에서.