But what if one of your contributors slips in a merge that uses the vulnerable code path of your dependency... Does this "not affected" marker still exist, and now you have vulnerable code? Does it disappear with each version?
What if someone maliciously adds a "not affected" marker? To a package they intend to exploit?
Edit: Again why the heck am I being downvoted?