Case Study: Watershed eliminates 85% of SCA noise with Coana reachability (now Socket)
Key results
The challenge
Watershed, the enterprise sustainability platform used by companies including Airbnb and BBVA, relies heavily on open source packages and runs a disciplined vulnerability-remediation process. Its existing SCA tool generated a high volume of false alarms, and determining whether the team was actually susceptible to a given vulnerability required significant investment from Security and Engineering, leaving teams doing reactive, time-consuming upgrades.
The solution
Watershed implemented Coana's SCA with reachability analysis, now part of Socket, across its Python and TypeScript stack, integrated via a zero-config GitHub Action that runs locally without sharing source code. Automated triaging removes irrelevant alerts, while contextual information and suggested fixes are surfaced for the vulnerabilities that remain.
“Now, only the most relevant 15% of vulnerabilities reach the engineering team, complete with contextual information and suggested fixes.”
JKJesse KrissHead of Security, Watershed
The results, in context
Coana removed 85% of irrelevant alerts, leaving only the most relevant 15% of vulnerabilities for the engineering team, complete with contextual information and suggested fixes. A few days after implementation, Watershed reduced its number of unresolved reachable vulnerabilities to zero.