← All finding types

known_cve

CWE-1395

Known Cve — a PullGuard finding type. Findings of this type appear in the PR comment, Step Summary, SARIF (GitHub Security tab / IDE viewers), and the HTML report, each with severity, location, and the remediation guidance below.

How to fix

Update vulnerable dependency to patched version low effort

npm audit fix

Reachability

Every CVE finding carries a reachability verdict — whether the vulnerable package is actually used by the code being scanned:

The verdict appears on the PR-comment row, in the JSON report (scaReachability), and in SARIF. Nothing is ever hidden: an unreached vulnerability is still reported in full.

Opt in with dependencies.reachabilityTiering: true in .driftrc.yml to have unreached vulnerabilities shown one severity band lower, annotated with their original severity and the reason. An unknown verdict never changes a severity, and a vulnerability on the CISA KEV catalog is never down-ranked.

Triage

Suppress a confirmed non-issue with a committed .pullguardignore entry (pullguard ignore locally, or comment /pullguard ignore <fingerprint> <reason> on the PR — the fingerprint is printed in the PR comment’s Triage section). Entries support expiresAt for time-boxed snoozes.

Security findings at major or critical severity — and any critical finding — always surface: .pullguardignore cannot hide them. The reviewed paths that keep them visible are acknowledged (reviewed, stays in reports) and, for a confirmed false positive, a reasoned false_positive entry — visible and audited, excluded only from the merge block.