But is upgrading libs ENOUGH? and does that make you feel confident that you are secured?
We are not claiming to solve using reachability analysis or claiming to solve anything but saving dev their time at this point!
My role, and others like me, need to get that critical vuln number down. Meaning yes, upgrading libs was enough.
Approaching vulnerability management from a developers view is a very narrow scope.