Best Practice - Waivers for Environment Specific Vulnerabilities

For this specific case (and maybe for other node based applications), couldn’t the scanner be updated to look for a package-lock.json and if it exists, check the packages.engines value?