The pervasive use of third-party libraries, while essential for development velocity, has introduced the difficult trade-off between addressing potential security risks and distracting engineering teams with unnecessary updates. Traditional Software Composition Analysis (SCA) tools fall short by flooding AppSec and developer teams with an overwhelming volume of vulnerability alerts, leading to wasted effort triaging, alert fatigue, and organizational friction between AppSec and developers. The evolution in addressing this problem is code-aware reachability analysis, that triages vulnerabilities based on the application’s code specific usage of the vulnerable function.