The direct vs transitive split helps a lot here. Most of that noise is transitive deps your app never actually calls with attacker-controlled input.
The actual split is on which environments the dependency exists in and who can control inputs in those environments. For most private companies who aren't running CI on an open source repo, the dev/prod split is the operative one that determines what you can safely ignore.