most of the nist/cve scanner logic has been moved to jq - but the fetcher implementation is currently in python (in envoy repo) we should repurpose the python package to just be a fetcher