Have we reached a point of no return on managing software dependencies?
paolomainardi.com
paolomainardi.com
Most security checking tools are incompatible with how Debian (and Ubuntu) deal with security issues: they backport security fixes to existing packages shipped with their stable distribution releases (so you'd have openfoo-1.4.3-debian4 instead of eg. openfoo-1.5.1, yet it wouldn't be vulnerable even if 1.4.3 upstream was).
While there is a caveat about false positives, I think it's irrelevant in the context of Debian since I trust Debian more than the tool author used.
I'll try to find some time later to play with it in depth as it seems to be an interesting set of tools!