Seems rush dependencies includes deprecated dependencies.
It depends on glob v7 which includes inflight (blackduck SCA scan recognizes that as vulnerable package)
└─┬ @microsoft/rush@5.165.0
└─┬ @microsoft/rush-lib@5.165.0
└─┬ @rushstack/package-extractor@0.11.8
└─┬ npm-packlist@2.1.5
└─┬ glob@7.2.3
└── inflight@1.0.6