How GitHub Advisory assigns vulnerabilities to same components coming from different package managers?

I am trying to understand how GitHub Advisory filters vulnerabilities, particularly in the context of Bootstrap 3.3.7. In the National Vulnerability Database (NVD), the following vulnerabilities are reported for Bootstrap 3.3.7:
CVE-2019-8… Continue reading How GitHub Advisory assigns vulnerabilities to same components coming from different package managers?