Skip to content
winfunc
SCA
Available

Know which dependencies put you at risk, and how to fix them.

Software composition analysis that reads every manifest and lockfile, checks whether your code actually reaches the vulnerable function, and turns each advisory into an upgrade your package manager understands.

  1. acme
  2. /billing-api
  3. /Dependencies
Packages412
Advisories7
Reachable2
package.jsonnpm
  • express4.19.2
  • body-parser1.20.2
  • axios1.6.0Reachable
  • follow-redirects1.15.4
  • pdfkit0.13.0
  • fontkit2.0.2
  • jsonwebtoken9.0.0
AdvisoryHigh

SSRF through a path-relative URL

CVE-2024-39338 · axios

Version
1.6.0 → 1.7.4
Called from
webhooks/preview.ts:61
Upgrade
bun add axios@1.7.4
Dependencies · reachabilityIllustrative data
What it does

Capabilities.

  • Reachability analysis: is the vulnerable function called from your code?
  • Direct and transitive dependencies from manifests and lockfiles
  • Advisories from OSV, GitHub Security Advisories, NVD, and RustSec
  • npm, PyPI, Go modules, Maven and Gradle, NuGet, RubyGems, crates.io, Packagist, Hex, and Pub
  • Fixed-version guidance and package-manager upgrade commands
  • SBOM export in CycloneDX and SPDX
  • License detection and policy checks for every package
  • Malicious and typosquatted package detection
  • CVSS score, aliases, and references for every advisory
  • Automatic rescans when a dependency file changes
How it works

From inventory to a verified upgrade.

  1. Step 1

    Inventory

    Read manifests and lockfiles to find direct and transitive packages.

  2. Step 2

    Match

    Correlate packages and versions with advisories, licenses, and known-malicious packages.

  3. Step 3

    Reach

    Trace from your code to the vulnerable function to rank what is exploitable.

  4. Step 4

    Upgrade

    Apply the fixed version and let the next scan confirm the result.

Why it matters

Built for decisions, not queues.

01

Reachable first

Most advisories never touch a code path you run. winfunc traces from your entry points to the vulnerable function, so the reachable few rise to the top and the rest stop interrupting your engineers.

02

Upgrade paths, not just alerts

Each advisory names the fixed version and gives the upgrade command for its package manager, then the next scan confirms the dependency is clean.

03

SBOM and licenses, on every scan

Export a CycloneDX or SPDX bill of materials for any revision, and flag licenses that conflict with your policy before they ship.

04

Alongside code findings

Dependency risk sits next to code, configuration, and secrets findings in the same workspace, so teams see the whole application in one place.

Start with one repository

Bring us your hardest codebase.
We'll bring the proof.

Scope a first audit with our security engineers. You get findings with traces, reproduction evidence, and patches ready for review.

A voxel chessboard: a bone rook and a red knight, with the traced path between them lit green after the fix was verified