holy crap this is huge news https://anchore.com/blog/say-goodbye-to-false-positives/. As someone who curates GitLabs vulnerability DB, I can tell you almost all of our problems stem from NVD/CPE mapping.