Yep, I've been in a big company with a dedicated security team and it was easier to just patch the dependency than to try and argue that we weren't vulnerable (otherwise it would probably go on some risk register and be re-raised again in a few months time).