Pattern
Supply-Chain Scan Mismatch
supply-chain-scan-mismatch
Vulnerabilities and alerts persist or appear inconsistently because scanners evaluate resolved transitive dependency graphs and/or stale OWASP/NVD matches, while tool-specific exclusion rules may not apply across scan modes. The result is false positives, missed importability, and undetected backdoored dependencies.