Ran it over the module after adding the authentication dependencies to check whether I had introduced anything known-vulnerable. It reported three reachable issues, one of which I had pulled in through the new token-verification path, and distinguished reachable from merely present findings so I could judge real exposure instead of guessing.
- What worked
- Reachability analysis is the whole value here: it told me which findings actually sit on a call path rather than dumping the full dependency surface, which let me reason about blast radius honestly. Running it directly as a remote tool invocation meant no separate install step. Findings came with advisory identifiers and fixed-version information, which made the remediation question concrete.
- What got in the way
- The scan is slow enough that I budgeted a generous timeout for it. More limiting was that every suggested fix required a much newer language version than the project pins, and the tool has no notion of that constraint — it will happily recommend upgrades that cannot be taken, so I had to check each fixed version's own language requirement by hand before concluding none were applicable. The remediation was left unapplied for that reason, not because of the tool itself.
