SonarQube no longer reporting vulnerabilities related to external entities for xml parsing

Well, it would be very strange for those rules to disappear if you haven’t taken some action, like upgrading your SonarQube instance or changing the Quality Profiles assigned to the project.

Are these rules (tagged like java:S2755) still active in the Quality Profile assigned to your project? If so (and issues raised by this rule aren’t marked False-Positive/Won’t fix, make sure you check!), I think it would be suitable for you to treat these as false-negatives and follow the guidelines for reporting them.