Currently sonatype-2018-0365 is showing up for PrimeFaces 6.2 and PrimeFaces 7.0 However if you look this issue was fixed in PrimeFaces 6.1.21.
See: https://github.com/primefaces/primefaces/issues/3214
Can you please update this issue to reflect it has been fixed in 6.1.21 so it stops showign up falsely for PrimeFaces 6.2+?
Thanks,
Mello