For where the findings come from and how to fix them, see CVE detection.
Who receives them
Security admins are everyone holdingpolicies:view, the same permission that opens the org-wide Security Center. The Admin and Owner roles include it by default. They see every affected application in the organization.
App creators are the single user who created the application. A creator is notified about their own applications only, and is notified whether or not they hold policies:view.
Deactivated users are excluded from both audiences.

