Local-first attack-path prioritization for dependency, SAST, DAST, and CSPM findings.
Reachability Advisor is a CI and IDE correlation layer for security scanner output. It answers one practical question:
Which findings are connected to reachable code, deployed assets, network exposure, identity access, and business impact?
It does not replace scanners. It consumes their evidence, connects it to deployment context, and ranks findings without treating missing evidence as safe.
- Ingests SBOM/SCA vulnerability data, source reachability evidence, SAST, DAST, CSPM/posture evidence, Terraform plans, Kubernetes manifests, and artifact identity manifests.
- Builds an evidence graph across assets, network paths, identities, source/runtime evidence, packages, and findings.
- Uses graph-first scoring to separate confirmed risk, potential risk, blockers, unknowns, and visibility gaps.
- Emits CI and developer outputs: JSON, SARIF, Markdown, IDE diagnostics, PR deltas, readiness reports, and an interactive HTML attack-path report with per-finding evidence stories.
- Stays local-first: no live cloud calls, telemetry, auto-suppression, or automatic "not affected" conclusions.
Run a complete no-cloud demo from checked-in samples:
python -m reachability_advisor demoKey outputs:
outputs/demo/summary.md- prioritized findings and visibility gaps.outputs/demo/findings.json- machine-readable findings with evidence and graph decisions.outputs/demo/reachability-graph.html- interactive attack-path report with a unified graph, risk sidebar, expandable finding nodes, and right-side context details.
See Quickstart for install steps, sample scans, release gates, and common workflow commands.
reachability-advisor init # writes .reachability.yml from what is in the repo
reachability-advisor doctor # what is missing, and the command that produces it
reachability-advisor scan # no flags; reads the configSee Quickstart for the full flow, including configuration layers and config explain.
- Dependency prioritization: combine SBOM and Grype/OSV/local vulnerability data.
- AppSec triage: correlate SAST and DAST findings with source, routes, artifacts, and runtime evidence.
- Deployment-aware risk: add Terraform plan, rendered Kubernetes evidence, and CSPM scanner output to account for network exposure, IAM, workload identity, and cloud posture.
- CI release gate: fail on confirmed or high-potential paths while reporting unknowns as visibility gaps.
- Developer feedback: export SARIF and IDE diagnostics only where real source locations exist.
Reachability Advisor keeps evidence types separate:
- Dependency vulnerabilities are package and vulnerability records.
- Static code weaknesses come from SAST/source evidence.
- Dynamic runtime observations come from DAST/runtime evidence.
- Cloud posture findings come from CSPM scanner output or native checks over local Terraform/Kubernetes evidence.
- Correlations link findings without merging or suppressing originals.
Details: Evidence model, Scoring, Input adapters.
- Prioritized findings JSON
- Markdown summary
- SARIF
- IDE diagnostics JSON
- Interactive HTML attack-path report: Attack Paths, Architecture, Evidence Paths, and Risk views
- Mapping, coverage, readiness, and baseline delta reports
Reachability Advisor is intentionally conservative. It does not make live cloud API calls, scan secrets, scan malware, create tickets, build a CNAPP inventory, suppress findings automatically, or claim exploitability from weak evidence. Missing evidence remains unknown.
- Documentation index - complete map of user, operator, design, and maintainer docs.
- Quickstart - install, demo, sample scan, release gate, PR delta, and fixture commands.
- Input adapters - scanner and context inputs accepted by the CLI.
- Evidence model and scoring model - how evidence becomes prioritized findings.
- Pipeline integration - CI, GitHub Actions, baselines, release gates, and generated artifacts.
- User-facing messages - wording rules for CLI errors, readiness blockers, reports, and web labels.
- Roadmap - stabilization priorities and release-readiness acceptance criteria.
- Production readiness review - feature grades and next stabilization focus.
The repository includes unit, fixture, scale, coverage, release-check, package, demo, SARIF, Markdown, JSON, diagnostics, and HTML output tests. The full local gate is documented in Quickstart.
