Ingress rule opened /admin to 0.0.0.0/0 in a hotfix. Severity: low.
API service running as root. Severity: low.
Vulnerable dependency installed and reachable from the API. Severity: medium.
Your ignored list just became interesting
Every one of those three was looked at once and waved off. Not exploitable on its own. Low risk for us. A dependency we don't even call.
Every one of those calls was reasonable. Every one was made about a single finding, on its own.
And here's what teams don't see coming: an app with no open vulnerabilities can still carry an attack scenario. The chain is built from what's there — not from what's unresolved.
Not one of these would have been actioned on its own.
Low. Low. Medium. Every one of them was looked at once and reasonably waved off. Together they are a route in.
Your pipeline already found all three. Your threat model still doesn't know.
The evidence exists. It went to a ticket queue instead of back into the model. That's the gap — and closing it is not a tooling problem, it's a workflow one.
Radar is the open-source scanner orchestrator behind Eureka. One command and it runs on your own code.
Open source, GPL-3.0. Orchestrates Opengrep, Semgrep, Gitleaks, Grype, OWASP dep-scan and Veracode into one SARIF report.
Read the source before you run it. That's rather the point.