We're SOC2 Type 2 certified and use Github Advanced Security as an SCA scanner. Every monday, Vanta reminds us to fix vulnerabilities to respect our SLAs
Literally this week: 26 new CVEs and Konvu found only 1 exploitable. Everything else is a false positive 🤷♂️
One auto-fix PR later, and we're hitting our SLAs without burning engineering time on noise that doesn't matter
Now imagine this at 10,000 CVEs a quarter. Let's talk 👻