CVE-2018-8292 alert in Github but not from SonarQube Scan

Hi Prasenjit and welcome to the community!

GitHub is warning you about a vulnerability in a dependency, so-called Software Composition Analysis (SCA). At this time we are focussing on Static Application Security Testing (SAST) though and do not provide SCA.