known_cveKnown Cve — a PullGuard finding type. Findings of this type appear in the PR comment, Step Summary, SARIF (GitHub Security tab / IDE viewers), and the HTML report, each with severity, location, and the remediation guidance below.
npm audit fix
Every CVE finding carries a reachability verdict — whether the vulnerable package is actually used by the code being scanned:
reached — a function the advisory names as affected is called.imported — the package is imported (production, or test code only).declared — it is in a manifest, but nothing imports it.transitive — it arrived indirectly, and nothing imports it.unknown — usage could not be determined for this project.The verdict appears on the PR-comment row, in the JSON report
(scaReachability), and in SARIF. Nothing is ever hidden:
an unreached vulnerability is still reported in full.
Opt in with dependencies.reachabilityTiering: true in
.driftrc.yml to have unreached vulnerabilities shown one severity band
lower, annotated with their original severity and the reason. An
unknown verdict never changes a severity, and a vulnerability on the CISA
KEV catalog is never down-ranked.
Suppress a confirmed non-issue with a committed .pullguardignore
entry (pullguard ignore locally, or comment
/pullguard ignore <fingerprint> <reason> on the PR — the
fingerprint is printed in the PR comment’s Triage section). Entries support
expiresAt for time-boxed snoozes.
Security findings at major or critical severity — and any critical finding —
always surface: .pullguardignore cannot hide them. The reviewed
paths that keep them visible are acknowledged (reviewed, stays in reports)
and, for a confirmed false positive, a reasoned false_positive entry —
visible and audited, excluded only from the merge block.