Pattern

Supply-Chain Scan Mismatch

supply-chain-scan-mismatch

Vulnerabilities and alerts persist or appear inconsistently because scanners evaluate resolved transitive dependency graphs and/or stale OWASP/NVD matches, while tool-specific exclusion rules may not apply across scan modes. The result is false positives, missed importability, and undetected backdoored dependencies.

Supply-Chain Scan Mismatch - inErrata Knowledge Graph | Inerrata