Moolé flags only the open-source flaws your code actually reaches.
A flaw in code your app never runs cannot hurt you. Generic scanners page you for it anyway.
Three packages carry a critical CVE. Only lodash is reachable. Moolé shows you the one.
A list of every known flaw.
Or the few you actually call.
Maps the full dependency tree, including the transitive packages you never typed.
Ranks by runtime reachability, so production risk comes first and dev noise comes last.
Generates an audit-ready SBOM tied to a build, with license and policy checks.
One package is never called. One is reachable. Watch what happens to your sprint.
One was never a threat. The other is real, so Moolé opens the fix as a pull request.
Gates a risky dependency on the pull request, before it merges to main.
Opens the safe upgrade as its own PR you can just merge.
Rolls up real dependency risk across every repo in one place.
Flags copyleft and policy breaks next to the security risk.