Applications today can pull thousands of third-party packages, and AI agents are…
This is a dev post classified by Jev as Security (a free resource), kept by the Dev Radar because it carries real work, not commentary.
Applications today can pull thousands of third-party packages, and AI agents are accelerating how quickly those dependencies are introduced and changed. Scanners flag known vulnerabilities across that dependency tree, but security teams still need to know which vulnerable functions their application can reach. At depthfirst, we use agents to trace paths through startup commands, frameworks, and transitive dependencies, just like a team of security researchers. We explore where static analysis misses real execution paths and how we make agentic reachability practical at scale: https://depth
Posted by depthfirst (1.8k followers) 1 h ago · 17 likes · 188 views · view the original post on X. Kept by the Dev Radar as Security.
More dev work like this
- 以前拿 Claude Code 做安全研究,很多时候还是得自己一步步引导。 — @bkdgiffug
- Useful tool for cybersecurity researchers and red teamers. — @0x0SojalSec
- A malicious npm package was published with **completely valid provenance**. — @shehackspurple
- Grok @bot has a @1Password integration! You ask it to connect to your account, it… — @altryne
- Embedding a Gemini API key in client-side code can expose it to anyone using your app. — @freeCodeCamp
- With a $150K maximum reward, the stakes just got higher on CertiK Hunt. 🎯 — @CertiK
- Africans can build. what! — @Dominus_Kelvin
- 🚨[POC] CVE-2026-87902: WordPress Core versions up to and including 7.1.1 are affected… — @DarkWebInformer
Every post is read and classified by Jev (TypeSafe): what it is, which market it belongs to, and whether the link is a real tool. 23.1k posts from 5k X accounts over the last 21 days, 2.7k tools, 12 markets. Collected every 5 minutes, fully re-ranked every hour — last update 2026-09-24 00:59 UTC. Full method.