Case Study: Starburst achieves 98.3% noise reduction and consolidates security tools with Endor Labs
Key results
The challenge
Starburst's previous SCA tool did not provide rationale for false positives, lacked support for transitive dependencies, and could not perform pre-deployment scanning, which forced vulnerability discovery to happen after deployment. The team needed accurate prioritization it could act on inside its existing developer workflows.
The solution
Starburst implemented Endor Labs for function-level reachability analysis across direct and transitive dependencies, with pre-deployment scanning integrated into its existing GitHub workflows. It also consolidated SCA, SAST, and secret detection onto the platform.
“Endor Labs is doing reachability analysis on transitive dependencies, which is really important to us and a huge deciding factor.”
AOAlex OleaDevSecOps Engineer, Starburst
The results, in context
Starburst reported a 98.3% noise reduction with Endor Labs and consolidated SCA, SAST, and secret detection into a single platform. Reachability analysis on transitive dependencies was cited as a key deciding factor.