DiscoverRisky BusinessRisky Biz Soap Box: How to measure vulnerability reachability
Risky Biz Soap Box: How to measure vulnerability reachability

Risky Biz Soap Box: How to measure vulnerability reachability

Update: 2025-08-14
Share

Description

In this Soap Box edition of the Risky Business podcast Patrick Gray chats with Socket founder Feross Aboukhadijeh about how to measure the reachability of vulnerabilities in applications.



It’s great to know there’s a CVE in a library you’re using, but it’s even better if you can say whether or not that vulnerability actually impacts your application.



They also talk about how Socket started out as a way to discover malicious packages in software projects, but these days it’s playing the CVE game as well.



This episode is also available on Youtube.





Show notes




Comments 
loading
In Channel
loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Risky Biz Soap Box: How to measure vulnerability reachability

Risky Biz Soap Box: How to measure vulnerability reachability