Pipeline
Lists installed packages, matches versions against published advisories, then runs Semgrep rules to check whether the vulnerable code is called.
Lists installed packages, matches versions against published advisories, then runs Semgrep rules to check whether the vulnerable code is called.