We are building cloud apps using the Connect Framework (ACSB to be precise). When we run security scans of our apps, several packages with vulnerabilities are identified in ACSB, compatible SpringBoot version, or other Atlassian dependencies.
I am sure Atlassian is also running these scans and evaluating each reported vulnerability to make sure it is not exploitable. But as a consumer of those libraries, we don't have data on which vulnerabilities were evaluated and which were not.
What is the recommended approach here? Are we simply recommended to use the latest versions of those libraries from Atlassian and ignore all reported vulnerabilities originating from those? Or is there are place where Atlassian shares its own vulnerability assessments?