We are requesting native support for Snyk Reachability Analysis metadata (or generic custom SARIF properties/tags) in the Harness STO UI.
Currently, when ingesting Snyk results using the native
type: Snyk
step, Harness STO's normalization engine strips out custom SARIF properties and tags. As a result, our developers lose all visibility into the reachability status of their vulnerabilities in the STO dashboard.
Please add the ability to display Snyk Reachability states (e.g., "REACHABLE", "NO PATH FOUND") natively in the STO UI. This feature is critical for our teams to filter out non-exploitable vulnerabilities and reduce security triage noise.
Created by Aadesh Bhardwaj
·