Policygenius
Products Used
Company Size
1,000+ Employees
Subscribe to our Newsletter
Software security at Policygenius
Challenges with scanning open source software
Introducing Semgrep Supply Chain
As soon as r2c developed a software supply chain product, Jess, who was already familiar with Semgrep, was excited to evaluate it against the tool Policygenius was using. With Semgrep Supply Chain, Jess was quickly able to identify a pattern where developers were using a specific vulnerable function across repositories. She was not able to identify how this pattern was used in their codebase using other SCA tools. She notified the developers, and they were able to fix the issue across many repositories. That was the ‘eureka’ moment for Jess!
Using reachability analysis, Semgrep Supply Chain can determine whether the code is using a vulnerable library and vulnerable function inside the library. If it is, then the finding is deemed reachable. If the code is just using the vulnerable library but not the vulnerable function, then the finding is deemed unreachable. Reachable findings help developers prioritize issues.
Why Policygenius loves Semgrep Supply Chain
Conclusion
About Policygenius