How to read a findings report without panicking
Severity tells you how bad it could be. Reachability tells you whether it can happen to you. You need both.
Look at a listing with two open findings and decide, in under a minute, whether they matter for what you want to do.
How to read a findings report without panicking works, in one picture
The same argument as the text, as a chain. Each step is what makes the next one possible.
- 1
Findings are normal, and a listing with none is not automatically better
Verified with findings is a first-class result on this site rather than a failure. Software of any size accumulates dependency advisories, and a badge that only ever said PASS would teach people to stop reading it.
A listing with zero findings and a listing with two findings can both be the right purchase. What changes the answer is which two.
- 2
Read severity and reachability together
The findings drawer, under the verification panelSeverity is how bad the issue would be if it were triggered. Reachability is whether the code path is one this software actually uses. A critical advisory in a dependency the listing never calls is worth less of your attention than a medium one in the request handler.
Every finding on this site carries both, and the report says which of the two we could determine automatically and which a person judged.
- 3
Weigh it against what you will let it touch
A finding is only as expensive as the access you grant. The same issue in a listing that reads a public API and one that holds your database credentials are not the same risk.
Read the permissions block on the same page before you decide. If the finding is in the part that touches your data, treat it as more serious than its label.
Given a finding, you can say whether it is reachable, what it would reach, and whether that changes your answer.
Read next
Severity tells you how bad it could be. Reachability tells you whether it can happen to you. You need both.
Every one shows its exact method, and the circumstances in which it is wrong. Free, and no account to look.