Case Study: Cedar cuts vulnerability alerts by 70% with Socket
Key results
The challenge
Over six years, Cedar's lean security team evaluated and tested multiple vulnerability-management solutions, including building an in-house application security platform, but struggled to find the data quality and stability its environment demanded. Previous tools generated thousands of findings with poor signal-to-noise ratios, making it hard to distinguish critical vulnerabilities from false positives and creating friction between security and engineering teams.
The solution
Cedar selected Socket for three capabilities: better data quality, higher relevance, and broader coverage across its repositories. Socket integrated into Cedar's GitHub environment with minimal effort, surfacing dependency context and reachability directly as comments in pull requests, and a Chrome extension gave engineers security data on hover instead of manual research.
“The big things that led us to Socket were: better data quality, higher relevance, and better coverage.”
TSTimothy SmithSecurity Engineering Manager, Cedar
The results, in context
Cedar reported that Socket reduced vulnerability alerts by 70%, enabling its lean security team to focus on high-impact work. Reachability reduced false positives, improving triage speed and confidence, and Socket's dependency context helped Cedar quickly determine exposure during major software supply chain incidents.