The SCA That Separates Real Findings From Noise
Reachability-first SCA. cupel scans your dependencies for known vulnerabilities, then traces whether a call path from your code actually reaches each one — and returns reachable, not reachable, or potentially reachable.
Your code never leaves your machine — your findings, your dashboard.


Most of Your Alerts Aren’t Your Problem
Traditional SCA flags every dependency that matches a known advisory — whether or not your code ever calls the vulnerable function. The result is a queue where real risk hides among alerts that don’t apply to you, and triage quietly becomes someone’s job. cupel is built to tell the two cases apart, and to show its work.


From Advisory to Verdict
advisory
The Advisory Names a Package, Not a Function
A security advisory tells you that a package, in some range of versions, is vulnerable. For npm it almost never says which function is the problem — so an alert at the package level can’t tell you whether you’re actually exposed.


symbol
cupel Derives the Vulnerable Function
cupel takes the two versions that matter — the last vulnerable one and the first fixed one — and diffs them at the syntax-tree (AST) level to find the function the fix actually changed. That function is the vulnerable symbol. cupel stores it as a fact — a name and a location — not a copy of the package’s source. When a fix can’t be pinned to a specific function, cupel doesn’t guess.


reachability
cupel Asks Whether Your Code Can Reach It
For each remaining finding, cupel asks one question: is there a call path from your application's entrypoints to that vulnerable function? That’s reachability. It searches out from your entrypoints and back from the vulnerable function at the same time, building only the slice of the call graph between them — so it answers without mapping your whole program. Most dependencies never reach this step; they’re ruled out earlier, cheaply.


verdict
A Verdict, With the Evidence Behind It
Every finding ends in a verdict you can act on — reachable, not reachable, or potentially reachable — with the call path and a confidence tier behind it. Each verdict is spelled out just below.


Works With Your Stack
- Languages
- JavaScript
- TypeScript
- Python
- GoPreview
- RustIn development
- Source control
- GitHub
- GitLab
- CI
- GitHub Actions
- GitLab CI/CD
- Any other CI, with the CLI
- Alerts
- Slack
- Microsoft Teams
- Discord
- Email digest
How cupel Compares
Against SCA tools that also analyse reachability, as each describes itself in its own documentation.
| cupel | Aikido | Endor Labs | Snyk | Socket | |
|---|---|---|---|---|---|
| Function-level reachability | Yes | Yes | Yes | Yes | YesEnterprise plan |
| Shows the call path | Yes | Yes | Yes | Yes | YesEnterprise plan |
| A separate result when it can’t decide | Yes | NoKept or lowered in severity | Yes | PartlyUnsupported cases only | Yes |
| Source code stays in your environment | Yes | PartlyLocal scanner, Pro plan | YesCI scans | No | Yes |
| Reachability on the free plan | Yes | Yes | No | Not documented | PartlyPackage level |
| GitHub integration | Yes | Yes | Yes | Yes | Yes |
| GitLab integration | Yesgitlab.com | Yes | Yes | YesEnterprise plan | YesEnterprise plan |
- Offered
- Partly
- Not offered
- Not documented
As each vendor’s own documentation described it on 26 September 2026.
potentially reachable Is an Answer
Static analysis has limits — dynamic imports, reflection, code that only exists at runtime. When cupel can’t rule a path out, it says potentially reachable and points at the exact hop it couldn’t resolve — or names why the check could not run. It never quietly marks a finding safe.
reachable
A real call path exists. cupel shows it hop by hop, with a confidence tier: high when every call along the path is resolved by type, medium when part of it rests on a looser, recall-preserving match.
not reachable
The vulnerable function is present, but nothing in your code can call it and the analysis ran to completion. This is the alert you can close, with the reason attached.
potentially reachable
A path might run through code static analysis can’t follow — a dynamic import, reflection — or the function-level check could not run. cupel names which, and whose it is to close, and never routes the finding to not reachable.
cupel would rather say potentially reachable than risk a false-clean — calling something safe when it isn’t — because that’s the one error a security tool doesn’t get to make.
Your Code Never Leaves Your Machine
— your findings, your dashboard.
- The scan runs where your code lives: your laptop, your CI.
- What syncs to the dashboard is findings — verdicts, call paths, confidence tiers. Code never uploads, on any tier.
- The enterprise tier is fully zero-egress: nothing syncs at all.
Why We’re Building cupel
Vulnerability disclosure is accelerating — NIST reports CVE submissions grew 263% between 2020 and 2025 — yet filtered for real-world exploitability, the patching burden has stayed roughly flat. The work is telling the two apart, and that is what cupel is for. The premise: a security tool earns trust by being precise about what it knows — and honest about what it doesn’t.
About cupelFAQ
How is cupel different from npm audit or Dependabot?
They match your dependency versions against advisories — package-level. cupel goes further: it derives the vulnerable function from the advisory’s fix, then checks whether any call path from your code reaches it. A version match says you might be exposed; a reachability verdict tells you whether you are — or says potentially reachable when it can’t rule a path out.
Which ecosystems does cupel support?
JavaScript and TypeScript (npm), and Python (PyPI). Go is in preview, and Rust is in development.
What does a potentially reachable verdict mean?
That cupel couldn’t rule out a path to the vulnerable function — usually a dynamic import or reflection breaks the trace. You see exactly which hop failed to resolve, or the named reason the check could not run. Potentially reachable means “we won’t guess”, not “probably fine”.
Is my code uploaded anywhere?
No. The scan runs locally; code never uploads, on any tier. Findings sync to your dashboard; the enterprise tier is fully zero-egress.
Can I use cupel today?
Yes. Create an account at app.cupel.sh. Five repositories are free, and each one after that is €5 a month.
See What’s Actually Reachable
Connect a repository and see every verdict with its evidence.
Start FreeFree for up to five repositories.