AI-Assisted Features in DevSecOps
Reduce supply chain risk with smarter vulnerability prioritization

Reduce supply chain risk with smarter vulnerability prioritization

1/7/2025 · Salman Ladha

What this post added

Introduced Static Reachability Analysis to identify exploitable vulnerabilities in open source components, a Known Exploited Vulnerabilities (KEV) Indicator to highlight actively exploited vulnerabilities, and the Exploit Prediction Scoring System (EPSS) to predict the likelihood of exploitation. These enhancements aim to reduce triage times and accelerate remediation cycles for AppSec teams. Future work includes integrating Rezilion's technology for automated fix merge requests, enriching package metadata with OpenSSF scorecard ratings, and improving license detection.

Read the original post ↗