You're Invited:Meet the Socket Team at BlackHat and DEF CON in Las Vegas, Aug 4-6.RSVP
Socket
Book a DemoInstallSign in
Socket

Changelog

What's new at Socket?

Back to changelog

July 30, 2025

Precomputed Reachability Analysis Is Now Available

Socket now automatically flags unreachable CVEs using precomputed reachability analysis, with no setup required.

  • Works from manifest files only (e.g., package-lock.json, requirements.txt)
  • Flags up to 80% of vulnerabilities as irrelevant
  • Instant results are are precomputed and cached for popular dependencies
  • Supports JavaScript, Python, JVM, .NET, and Go (Ruby/Rust coming soon)
  • New “CVE Reachability” section in alert modals + filter by reachability
  • Unreachable CVEs now default to "monitor" action

It's available now for all Team and Enterprise users. Read the announcement for more details and check out the Reachability Analysis docs to see a full breakdown of features, tiers, and what's coming next on our roadmap.