The SCA That Separates Real Findings From Noise

Reachability-first SCA. cupel scans your dependencies for known vulnerabilities, then traces whether a call path from your code actually reaches each one — and returns reachable, not reachable, or potentially reachable.

Start FreeSee How It Works

Free for up to five repositories.

Your code never leaves your machine — your findings, your dashboard.

The cupel dashboard: 2 reachable, 2 potentially reachable and 16 not reachable advisories, each broken down by tier.The cupel dashboard: 2 reachable, 2 potentially reachable and 16 not reachable advisories, each broken down by tier.
The dashboard, with example data.

Most of Your Alerts Aren’t Your Problem

Traditional SCA flags every dependency that matches a known advisory — whether or not your code ever calls the vulnerable function. The result is a queue where real risk hides among alerts that don’t apply to you, and triage quietly becomes someone’s job. cupel is built to tell the two cases apart, and to show its work.

The findings list: each advisory with its repository, package, verdict and severity.The findings list: each advisory with its repository, package, verdict and severity.

From Advisory to Verdict

advisory

The Advisory Names a Package, Not a Function

A security advisory tells you that a package, in some range of versions, is vulnerable. For npm it almost never says which function is the problem — so an alert at the package level can’t tell you whether you’re actually exposed.

An advisory in the dashboard: its ids, the package and version it affects here, and links to read it.An advisory in the dashboard: its ids, the package and version it affects here, and links to read it.

symbol

cupel Derives the Vulnerable Function

cupel takes the two versions that matter — the last vulnerable one and the first fixed one — and diffs them at the syntax-tree (AST) level to find the function the fix actually changed. That function is the vulnerable symbol. cupel stores it as a fact — a name and a location — not a copy of the package’s source. When a fix can’t be pinned to a specific function, cupel doesn’t guess.

The vulnerable function a finding is about, and how its package got into the project, from the manifest down.The vulnerable function a finding is about, and how its package got into the project, from the manifest down.

reachability

cupel Asks Whether Your Code Can Reach It

For each remaining finding, cupel asks one question: is there a call path from your application's entrypoints to that vulnerable function? That’s reachability. It searches out from your entrypoints and back from the vulnerable function at the same time, building only the slice of the call graph between them — so it answers without mapping your whole program. Most dependencies never reach this step; they’re ruled out earlier, cheaply.

How the code reaches the vulnerable function: each call from the entrypoint, by file and line.How the code reaches the vulnerable function: each call from the entrypoint, by file and line.

verdict

A Verdict, With the Evidence Behind It

Every finding ends in a verdict you can act on — reachable, not reachable, or potentially reachable — with the call path and a confidence tier behind it. Each verdict is spelled out just below.

The route cupel followed to each vulnerable function, every step with its file and line.The route cupel followed to each vulnerable function, every step with its file and line.

Works With Your Stack

Languages
  • JavaScript
  • TypeScript
  • Python
  • GoPreview
  • RustIn development
Source control
  • GitHub
  • GitLab
CI
  • GitHub Actions
  • GitLab CI/CD
  • Any other CI, with the CLI
Alerts
  • Slack
  • Microsoft Teams
  • Discord
  • Email digest

How cupel Compares

Against SCA tools that also analyse reachability, as each describes itself in its own documentation.

cupelAikidoEndor LabsSnykSocket
Function-level reachabilityYesYesYesYesYesEnterprise plan
Shows the call pathYesYesYesYesYesEnterprise plan
A separate result when it can’t decideYesNoKept or lowered in severityYesPartlyUnsupported cases onlyYes
Source code stays in your environmentYesPartlyLocal scanner, Pro planYesCI scansNoYes
Reachability on the free planYesYesNoNot documentedPartlyPackage level
GitHub integrationYesYesYesYesYes
GitLab integrationYesgitlab.comYesYesYesEnterprise planYesEnterprise plan

As each vendor’s own documentation described it on 26 September 2026.

potentially reachable Is an Answer

Static analysis has limits — dynamic imports, reflection, code that only exists at runtime. When cupel can’t rule a path out, it says potentially reachable and points at the exact hop it couldn’t resolve — or names why the check could not run. It never quietly marks a finding safe.

reachable

A real call path exists. cupel shows it hop by hop, with a confidence tier: high when every call along the path is resolved by type, medium when part of it rests on a looser, recall-preserving match.

not reachable

The vulnerable function is present, but nothing in your code can call it and the analysis ran to completion. This is the alert you can close, with the reason attached.

potentially reachable

A path might run through code static analysis can’t follow — a dynamic import, reflection — or the function-level check could not run. cupel names which, and whose it is to close, and never routes the finding to not reachable.

cupel would rather say potentially reachable than risk a false-clean — calling something safe when it isn’t — because that’s the one error a security tool doesn’t get to make.

Your Code Never Leaves Your Machine

— your findings, your dashboard.

Why We’re Building cupel

Vulnerability disclosure is accelerating — NIST reports CVE submissions grew 263% between 2020 and 2025 — yet filtered for real-world exploitability, the patching burden has stayed roughly flat. The work is telling the two apart, and that is what cupel is for. The premise: a security tool earns trust by being precise about what it knows — and honest about what it doesn’t.

About cupel

FAQ

How is cupel different from npm audit or Dependabot?

They match your dependency versions against advisories — package-level. cupel goes further: it derives the vulnerable function from the advisory’s fix, then checks whether any call path from your code reaches it. A version match says you might be exposed; a reachability verdict tells you whether you are — or says potentially reachable when it can’t rule a path out.

Which ecosystems does cupel support?

JavaScript and TypeScript (npm), and Python (PyPI). Go is in preview, and Rust is in development.

What does a potentially reachable verdict mean?

That cupel couldn’t rule out a path to the vulnerable function — usually a dynamic import or reflection breaks the trace. You see exactly which hop failed to resolve, or the named reason the check could not run. Potentially reachable means “we won’t guess”, not “probably fine”.

Is my code uploaded anywhere?

No. The scan runs locally; code never uploads, on any tier. Findings sync to your dashboard; the enterprise tier is fully zero-egress.

Can I use cupel today?

Yes. Create an account at app.cupel.sh. Five repositories are free, and each one after that is €5 a month.

See What’s Actually Reachable

Connect a repository and see every verdict with its evidence.

Start Free

Free for up to five repositories.