Read more at:
That does not mean every Fix Now finding should automatically block every release. A defensible CI policy can use Fix Now as one blocking condition while treating a CISA KEV match, confirmed reachability, or a critical production asset as independent reasons to stop. Monitor and Lower Priority findings can flow into tracking unless local context raises them.
This is a better model than blocking on every high-severity advisory. A gate that produces constant noise will eventually be bypassed. A gate that explains why a finding is elevated, and which additional evidence can override the default, is easier to trust.
A research direction
At Colorado State University, researchers are exploring where this model can go further. Rakesh Podder, Viktoria Koscinski, and Indrajit Ray developed CAPE (Context-Aware Prioritization Engine), a framework that enriches each CVE with deployment-specific evidence — reachability, centrality, and exploitability analysis — producing a ranked priority score using Analytic Hierarchy Process (AHP). Evaluated across 30 open-source projects and over 6,000 scanner-reported CVEs, their findings show that 43.3% of scanner-reported CVEs are statically unreachable (53.1% for TypeScript and JavaScript; 27.4% for Python). In the most extreme case, that rate reached 76.1%.


