The unreasonable part is that CVEs can be assigned for subjective things requiring deciding whether it matters. They say known vulnerabilities in those databases need to be fixed and it seems reasonable to require knowing which projects you ship and shipping the patches for them.