Vulnerable dependencies caught
before an attacker finds them
A dependency scanner that lists two hundred CVEs with no sense of which ones actually matter for your app gets ignored within a week. We build an agent that scans your dependencies continuously, ranks each finding by whether the vulnerable code path is actually reachable in your codebase, and opens a pull request with the fix for anything genuinely urgent.
The process today
Dependency scanners exist in most stacks already, and most teams have learned to ignore them, because the output is a long list of CVEs sorted by a severity score that does not account for whether the vulnerable function is ever actually called in your code. A critical-rated vulnerability in a transitive dependency’s test helper, never invoked in production, gets the same red banner as one in a library your app calls directly on every request. Faced with that list weekly, most teams either triage none of it or spend hours manually checking reachability by hand.
The second cost is patch fatigue combined with patch risk. Bumping a dependency version to fix a vulnerability can itself break something, so teams that do patch often batch updates together, which makes it harder to isolate what broke if something does, and teams that do not patch accumulate risk silently until an audit or an incident forces the issue.
The third is the software bill of materials nobody maintains until a customer or a compliance review asks for one, at which point building it from scratch for a codebase with hundreds of dependencies takes longer than it should.
What the agent does
The agent scans every dependency across the repositories in scope on a schedule and on every merge, checking each finding against known CVE databases and then against your actual code to see whether the vulnerable function or code path is reachable from code you call. Findings get ranked by that reachability check combined with severity, so a critical CVE in code your app actually executes surfaces first, and a critical CVE in an unused test utility does not drown it out.
For a straightforward version bump that fixes the issue without a breaking change, the agent opens a draft pull request with the updated dependency and a note on what the fix addresses, ready for your normal review and test cycle. For anything requiring a code change beyond a version bump, it opens an issue describing exactly what needs to change and why. A software bill of materials is kept current and attached to every release, ready to hand to a customer or an auditor without rebuilding it from scratch. Typical integrations: GitHub, GitLab or Bitbucket for the repository and pull request flow, Slack or email for the weekly digest.
What stays with humans
Merging the pull request, deciding to delay a patch for a specific release window, and accepting a finding as a known, tolerated risk all stay decisions your team makes; the agent surfaces the risk clearly and proposes the fix, it does not merge anything on its own. Judgment calls on a finding with no clean upstream fix yet, where the choice is between a workaround, a version pin, or accepting the exposure temporarily, go to a person with the context the agent has gathered.
Guards
Every finding, its reachability assessment, and whatever was done about it, patched, exempted, or still open, is logged, so an audit or a customer security questionnaire has a clear answer ready. The agent never merges its own pull requests; everything goes through your normal review and CI process. A kill switch pauses automatic pull request creation while keeping the scanning and alerting running, useful during a release freeze.
Price and timeline
| Option | Price | What it covers | Timeline |
|---|---|---|---|
| Single automation | from $800 | Up to a handful of repositories, reachability ranking, automatic patch pull requests | 4 to 8 days |
| Department package | from $2,200 | Dependency scanning plus secrets rotation and access reviews across your stack | 2 to 4 weeks |
Running cost is usually $15 to $45 a month in model usage depending on repository count and scan frequency.
Related
This pairs well with secrets rotation and access reviews and offboarding as part of the same security hygiene program, and with CI/CD pipelines with AI code checks so a dependency bump goes through the same risk review as any other change. Full package details are on the AI agents service page and the automation-everything overview; for how we handle security on infrastructure we run ourselves, see the secure infrastructure case study and the secure messenger case study.
Not sure which of your two hundred CVE alerts actually matter? Get in touch and we will run a reachability pass on your current list.
Tired of doing this by hand? We can take the whole routine off your team, not just this step: Routine takeover, from $400 →
FAQ
How much does dependency and vulnerability scanning cost?
From $800 for up to a handful of repositories, live in 4 to 8 days. A larger codebase or multiple teams usually run $1,500 to $2,500.
How is this different from the free scanner GitHub already runs?
GitHub's built-in alerts list every known CVE regardless of whether your code actually calls the vulnerable function. This agent checks reachability first, so your team sees the handful that matter instead of a list of two hundred that mostly do not apply.
Does it just open pull requests automatically?
For a simple, non-breaking version bump with a clean fix, yes, as a draft pull request for review. For anything that requires a code change beyond a version bump, it opens an issue with the specific fix needed and leaves the change to your team.
What about vulnerabilities in our own code, not dependencies?
This automation focuses on third-party dependencies and the software supply chain. A broader code security review is a separate, deeper engagement; ask us and we will scope it.
Can we exempt a finding we have already assessed as low risk?
Yes, an exception list lets your team mark a specific finding as reviewed and accepted, with a reason and an expiry date, so it stops resurfacing every week without being silently forgotten forever.