Semgrep Product Update

Dependency paths now in SBOM exports and the Issue API

Teams need to know not just which dependencies are vulnerable, but how a vulnerable transitive package connects back to a direct dependency. Dependency path data is now available in two places: SBOM exports include the full dependency graph in the CycloneDX dependencies section, and the Issue API now shows which direct dependency introduced each vulnerable transitive package.

profile image
Pablo Estrada