# Going beyond reachability to prioritize what matters most

DevFeed: [Going beyond reachability to prioritize what matters most](<https://devfeed.tech/articles/going-beyond-reachability-to-prioritize-what-matters-most-7782.md>)

Original publisher: [Read original article](<https://snyk.io/blog/Reachability-for-vuln-prioritization/>)

Author: Jamie Smith

Published: 2024-10-01T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [devops](<https://devfeed.tech/tags/devops.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

## AI overview

The article examines the difficulty of prioritizing open-source vulnerabilities across direct and transitive dependencies. It argues that static reachability and severity signals need additional risk context to guide remediation.

## Source excerpt

While static reachability can help teams better understand their app vulnerabilities, they must be paired with other types of context and risk insights.