Dependencies
Reachability
Which direct dependency pulls a transitive package in.
A transitive package is only in your build because something you declared depends on it. Interopt reads that chain from the lockfile, so you know which direct dependency to move.
Reached via
Open a transitive package and the Reached via block shows the shortest chain from each direct dependency down to it.
- The first name in each chain is the direct dependency — the only name you can actually change.
- A package can arrive by several routes, and each has to be dealt with on its own, so every direct dependency that reaches it gets its own chain.
- When there are more routes than fit, the block says how many it is holding back.
Direct packages
A package you declared is not reached through anything, so its sheet shows where it is declared instead of a route.
Why it matters
A vulnerable transitive package with no route from your code cannot be fixed by bumping a dependency, and is not urgent. One with a single direct root is a one-line change. Reachability is the difference.
