┌───────────────────────────────────────────┐
└─ automated security review · evidence-grounded ─┘
Lockfile-based CVE scanning treats every dependency as equally dangerous. It isn't. Here's how reachability analysis tells the difference — and where it still falls short.