
Reachability has become a buzzword in the world of application security (AppSec). While security teams see reachability as a prioritization tool, developers often push back against additional tech debt—especially when it involves upgrading open-source packages.
This divergence raises a critical question: Is it more valuable to provide developers with focused, actionable context or to deliver comprehensive reachability insights for every vulnerability?
Let’s use NPM as an example to unpack this debate. Here's what the data reveals:
From this data, 5.3% of all high and critical vulnerabilities on NPM can be prioritized as top-tier risks. These are easier for security teams to justify fixing, and they resonate better with developers. The Value of Code Risk Prioritization for Developers Why does this matter? Developers are inundated with security tasks, many of which they view as blockers to their primary objective: shipping quality software. By narrowing focus to a small, high-priority subset of vulnerabilities, security teams can better align with developer goals and drive faster remediation. The key question becomes: How much value does reachability add when the developer focus is on the subset of vulnerabilities that matter most? Would doubling down on developer-first context—such as actionable insights on real-world exploitability and high-priority risks—yield greater value? Case Studies in Context Consider these real-world insights into NPM packages:
These examples illustrate that download counts alone don’t capture risk. A package’s exploitability, historical relevance, and potential reachability within a codebase are critical metrics for prioritization. A Developer-Centric Approach to Security The goal isn’t just reducing vulnerabilities—it’s making secure coding a seamless part of the development process. To achieve this, AppSec strategies should:
As AppSec evolves, the debate between providing full reachability context and developer-focused insights will persist. However, data shows that prioritizing the vulnerabilities most likely to impact production environments not only reduces risk but also fosters better collaboration between security and development teams. The point is... reachability on its own is not enough. Risks need to be detected, prioritized, and triaged in a way that aligns to developer focus and workflows. In the end, effective AppSec isn't about finding every vulnerability—it’s about fixing the right ones, faster.
Integrate Arnica ChatOps with your development workflow to eliminate risks before they ever reach production.