01Introduction
A CVE in a package you depend on is not the same as a vulnerability in your application. If your code never calls the affected function, an attacker cannot either. Reachability analysis is how teams stop treating those two things as equal.
02What is Reachability analysis?
Reachability analysis determines whether a known vulnerability in a dependency is actually invoked by the application, by tracing call paths from the app's entry points to the vulnerable code.
It is the prioritization layer on top of SCA and a practical form of risk-based vulnerability management. The same idea, applied to cloud infrastructure, is attack path analysis.
03How Reachability analysis works
Reachability connects advisories to real code paths.
- 1.
Locate the flaw
Map each advisory to the specific functions or methods in the package that contain the vulnerability.
- 2.
Build the call graph
Trace calls from your entry points, such as HTTP handlers or CLI commands, through your code and into dependencies.
- 3.
Follow the data
Check whether attacker-controlled input can reach the vulnerable function with the values needed to trigger it.
- 4.
Classify
Mark each finding reachable, unreachable or unknown, and rank the reachable ones first.
04Threats and risks
Without reachability, teams fix the wrong things.
Wasted upgrades
Engineers spend sprints bumping packages for vulnerabilities that were never exploitable.
Buried criticals
The one reachable issue is lost among hundreds of theoretical ones.
Dynamic calls
Reflection, dynamic imports and plugins make naive call graphs miss real paths.
Stale verdicts
A path that was unreachable last month becomes reachable when a new feature ships.
05How Parameter helps
Reachability is the core of Parameter Supply Chain.
Traced, not guessed
Agents follow call graphs and data flow across direct and transitive dependencies.
92% less noise
Most advisories are filtered out as unreachable, so the list that remains is the list worth fixing.
Re-checked on every change
Pull requests are re-analyzed, so a newly reachable path is caught before it merges.

