We are currently scanning for known vulnerabilities in our dependency trees but Tuleap also ships and uses other tools like Git, Gitolite, pnpm... These tools are not directly visible in Tuleap dependency tree so they are not scanned. They should be.