The dependency toggle was on the settings page; what the check found was not.
repo deps status emitted an anonymous struct, so the web had nothing to decode.
It becomes control.DepsOut / control.DepBehind — named payloads, covered by
TestNamedPayloadsRoundTrip and TestPayloadFieldsAreTagged like the rest — and
settingsForm dispatches the command and renders last check, last error, a link
to the tracking issue, and the rows that are behind.
TestSettingsPageRendersDepsStatus renders the page against a populated payload,
so a renamed field fails rather than blanking a cell; TestDepsEnableDisable
checks the page reports the state the command does. Parity row and note updated.
Closes #164