We run nsp on our production services in CI before merge. The number of false positives I have tracked down is infinitely higher than the number of vouln's found. I literally mean this, we have never seen one disclosure which resulted in a viable attack on our production services.
For example, recently a bunch of ReDOS voulns were reported in popular libraries. None of which were in code paths hit by our configurations.
So needless to say, I think this is a sensationalist headline.