Tools
Strix Adds Contextual CVSS and Source-to-Sink Reachability Evidence to Dependency Findings — Seven Commits on 2026-08-17 Alone
usestrix/strix, the open-source AI penetration-testing agent (53,617 stars, +856 in a day, 5,747 forks), landed a burst of commits today that compute a full eight-metric contextual CVSS environmental breakdown for dependency findings and now *require* a source-to-sink trace in the reachability evidence, not just CVSS reasoning. The team iterated in public within hours — first dropping per-metric reasoning, then re-requiring reasoning only for surviving metrics, then requiring usage evidence on every dependency report. This is the concrete answer to SCA noise: a CVE only reports as exploitable if the agent can show the call path that reaches it.
Source
↳ Follow the thread