Library-level vulnerabilities for npm, PyPI, Go, Maven, RubyGems, NuGet, Composer, Rust — mapped to ATT&CK via CWE→CAPEC bridge