Find and investigate any dependency.
Search your software inventory and inspect a package without losing its application context. Move from direct and transitive dependencies to vulnerabilities, reachability, available fixes, and license information in the same workspace.
Search the inventory. Inspect the dependency. Decide what to fix.
A new advisory names a package. Are you affected?
Start with the software you actually ship. Direct and transitive dependencies remain linked to the application that uses them.
Search the dependency inventory
Search for a package name. Results include direct and transitive dependencies.
See which routes use the package
The Routes tab connects the selected package and version to the affected application routes.
Inspect the vulnerability details
Open a finding in the Vulns tab to review the advisory, affected versions, and available fix.
Narrow the inventory by reachability and KEV
Combine the reachability and KEV filters to focus on packages with known exploited vulnerabilities in reachable code.
Check the package’s license policy result
The Licenses tab shows the detected license and whether your policy allows it.
Reassess findings when the evidence changes.
Farion updates vulnerability intelligence several times per day and retains every advisory version.
Advisory changes
New references, altered severity, or updated affected versions.
Exploit signals
EPSS movement, a KEV listing, or fresh exploit information.
Fix availability
A newly available fix changes the remediation options for an existing finding.
Export the result, not just the raw inventory.
Every export is generated from the same underlying dependency context you investigated.
SBOM and VEX
CycloneDX and SPDX SBOMs, plus VEX for application dependencies.
Reports
License reports, SARIF, PDF, Finding History, and Audit Logs.
API
The same dependency context, available programmatically.
Frequently asked questions
Farion combines dependency usage, vulnerable-function reachability, tainted paths, application routes, vendor advisories, KEV, EPSS, exploit information, and AI exploitability analysis.
Yes. Container and VM inventories can be collected in CI/CD or from a Kubernetes cluster and correlated with the source application. VEX is available for application dependency findings, not for operating-system package findings.
Search your own dependency inventory.
Bring a package or vulnerability you want to investigate and walk through it with our team.