Coverage and concrete signals
For vulnerable dependencies, inspect the concrete scope below instead of relying on a category label. Tie the advisory to the exact manifest and lockfile version, reachable package path, severity, and available fixed release.
- Focus: Detect known-vulnerable package versions in manifests or lockfiles.
- Workflow: Rule ID: RADAR-SCA-VULNERABLE
- Coverage and concrete signals: RADAR-SCA-VULNERABLE, unsafe pattern, safer pattern, Dependency security
FocusExact file location, rule context, severity, confidence, and remediation guidance.Boundary
Detect known-vulnerable package versions in manifests or lockfiles.Tie the advisory to the exact manifest and lockfile version, reachable package path, severity, and available fixed release.An unused or unreachable dependency may be lower risk but still needs ownership and upgrade tracking; verify reachability and retest after the fixed version lands.