The exact version that ships
A rule like anything from 1.5 upwards is not an answer. Recorded here is the version that was installed.
Black box, grey box or white box. Interopt tests with whatever you give it.
Start your first free runEvery package that ends up inside your applications, what brought it there, and which of them a known vulnerability affects. Kept current by the same runs that test the application itself.

Each package opens into what affects it, what brought it in and what it takes to move it.
Matched against the version in front of it, not against a name that looks similar. The resolved version is the one treated as proven; the range someone typed in a manifest is shown separately.

A transitive package is only in your build because something you declared depends on it. The shortest chain from each direct dependency is shown, so you know which name you can actually change.
The full list runs to a thousand entries. The stack is the short version a person actually reads: the languages, frameworks, databases and infrastructure an asset is built on.
Assets
Preview upgrade reads the repository and shows the manifest edits for the fixed version, along with any package coupled to it, across every place the package is listed.

Built from what actually gets installed, not from what someone wrote down.
A rule like anything from 1.5 upwards is not an answer. Recorded here is the version that was installed.
Most of what an application installs, nobody on your team picked. That is where the risk sits.
In a large codebase the same package is listed in several projects, and changing one leaves the rest behind.
The shortest chain back to something you did choose, which a plain list cannot answer.
Connect a repository and the first run returns the inventory alongside the findings, with the chains and the fix versions already worked out.