
Xpsd: Open-Source Tool to Determine CVE Reachability in Codebases
open-sourcecybersecurityCVEGitHubcode-scanningSARIFtool
Xpsd is an open-source tool designed to determine whether a reported CVE is reachable in a specific codebase. It processes CVEs or scan reports (e.g., from Grype/Trivy) and provides a verdict, evidence, and call paths when available. The tool outputs results in SARIF format for integration with GitHub code scanning and operates as a GitHub Action, Copilot, or with custom models. It is released under the Apache-2.0 license and reached version 1.0.