Open-Source · Software Composition Analysis

Open-source risk, without the noise.

Moolé flags only the open-source flaws your code actually reaches.

01 · The problem

You did not write most of your app.

A flaw in code your app never runs cannot hurt you. Generic scanners page you for it anyway.

your-app the code you own express direct dependency report-utils direct dependency image-tools direct dependency mime-types transitive · clean safe-buffer transitive · clean lodash 4.17.4 transitive CVE · reachable handlebars 4.0.1 transitive · never called CVE · present, not reachable minimatch 3.0.2 transitive · never called CVE · present, not reachable
path your code actually calls vulnerable and reachable vulnerable but never called

Three packages carry a critical CVE. Only lodash is reachable. Moolé shows you the one.

A list of every known flaw.
Or the few you actually call.

02 · How it works

Three parts, one honest answer.

01

Discover

Maps the full dependency tree, including the transitive packages you never typed.

02

Prioritize

Ranks by runtime reachability, so production risk comes first and dev noise comes last.

03

SBOM & Governance

Generates an audit-ready SBOM tied to a build, with license and policy checks.

03 · A real example

Same CVE. Two very different weeks.

One package is never called. One is reachable. Watch what happens to your sprint.

yarn.lock · what other tools seethe old way
"lodash@4.17.4": version "4.17.4" # CVE-2019-10744 · CRITICAL # (prototype pollution in defaultsDeep) your code: import { get } from "lodash" # defaultsDeep is never imported scanner verdict: CRITICAL. block the build. page on-call. file the ticket. team spends a sprint on a flaw nothing in this app runs.
moolé · what actually matterswith Moolé
lodash@4.17.4 · CVE-2019-10744 vulnerable fn: defaultsDeep your code calls it? no reachable: no → severity downgraded → no action needed express → cookie@0.3.1 · CVE-... vulnerable fn: parse() your code calls it? yes reachable: yes → fix PR opened → safe upgrade to 4.17.21

One was never a threat. The other is real, so Moolé opens the fix as a pull request.

04 · In your workflow

It shows up where the work happens.

01

PR enforcement

Gates a risky dependency on the pull request, before it merges to main.

02

Automated remediation

Opens the safe upgrade as its own PR you can just merge.

03

Portfolio view

Rolls up real dependency risk across every repo in one place.

04

License detection

Flags copyleft and policy breaks next to the security risk.

Other tools hand your team homework. Moolé hands them a merge button.