
1/7/2025 · Salman Ladha
What this post added
Introduced Static Reachability Analysis to identify exploitable vulnerabilities in open source components, a Known Exploited Vulnerabilities (KEV) Indicator to highlight actively exploited vulnerabilities, and the Exploit Prediction Scoring System (EPSS) to predict the likelihood of exploitation. These enhancements aim to reduce triage times and accelerate remediation cycles for AppSec teams. Future work includes integrating Rezilion's technology for automated fix merge requests, enriching package metadata with OpenSSF scorecard ratings, and improving license detection.