VulnTriage.
Vulnerability triage grounded in evidence from the code.
Selected work
- Built a Python CLI that matches Trivy findings to imports and call sites extracted with Tree-sitter.
- Kept uncertain findings open for review and added a strict mode that blocks automatic dismissals when files are skipped.
- Exported triage decisions as CycloneDX VEX and OpenVEX JSON for downstream tools and CI.
- Added optional AI analysis with Pydantic-validated responses. Advisory output leaves rule-based classifications unchanged.
- Used local EPSS and KEV data to prioritize findings offline, with an explicit refresh option for updated snapshots.
Built with
Python · Trivy · Tree-sitter · Pydantic · Pytest · OpenAI API · Typer
Screenshots
