Technical SEO has acquired a reputation for being a checklist exercise, which is unfortunate, because the checklist items are the least valuable part of it. Anyone can determine that a canonical tag is missing. The difficult work is establishing whether that missing tag is causing a problem on this particular site, given how its URLs are generated and what its analytics show.
The questions worth answering are structural. Can a crawler reach every page that matters, in a reasonable number of steps, without wasting its budget on variations that should never have existed? Once it arrives, is the content there, or does it appear only after JavaScript executes? Does the site tell a consistent story about which address is canonical, or does it contradict itself between the sitemap, the internal links and the tags themselves?
Those questions have different answers on every site, and the answers rarely correspond to how many items a tool flagged.