If I understand the diagram in the README right, this one is no different. It just analyzes changelogs of not-yet-updated packages, which are in turn prepared by distribution maintainers. NVD is just used for adding details of the CVEs that has been found.