I've seen startups claiming to solve these with reachability analysis. I think upgrading libs regardless could be a better solution, particularly for high-risk vulnerabilities.
My role, and others like me, need to get that critical vuln number down. Meaning yes, upgrading libs was enough.
Approaching vulnerability management from a developers view is a very narrow scope.