Bombon generates Package URLs, such as these: ``` pkg:nix/glibc@2.39 ``` As far as I can see, there is no CVE data source for these PURLs. Is there any advice on how to handle these for vulnerability analysis?