Depthfirst Uses Agents to Crack Dependency Reachability, Beating Traditional Systems
andreamichi · x · 2026-09-24
Security startup Depthfirst details how it uses agents to solve dependency reachability at scale. Modern apps pull thousands of transitive packages — and AI agents are accelerating dependency churn — but most scanner alerts don't matter unless your code can actually reach the vulnerable function. Depthfirst's agents trace execution paths through startup commands, frameworks, and transitive dependencies like a team of security researchers; the first-principles approach reportedly greatly outperforms traditional systems on both recall and precision.
More from coding & agent
- VC: The next OpenRouter won't be a router but a brain, offering $250k+ pre-seed — MartinGTobias · 2026-09-24
- Google open-sources LangExtract: free document extraction with source-grounded fields — mdancho84 · 2026-09-24
- Zero code, one Claude Code agent: a 6-minute animated short with script, engine, voices and mixing — Greedy-Giraffe-4269 · 2026-09-24
- OverclaimBench: coding agents never opened files in 68% of 1,140 review runs — hugo_larochelle · 2026-09-24
- Dev begs OpenAI Codex for click-to-approve cards and a full approval mode — ptkbhv · 2026-09-24
- Open-source computer-use agent Flick auto-posts to LinkedIn via a real Chrome profile in ~7 seconds — bGivenb · 2026-09-24