Healthy upstream

Verified source · trusted flow

Risky upstream

Backdoored package · compromised repo

Maintainers

The humans whose keys could ship the next version.

Dependencies

Verified source · trusted flow

Registries

Provenance, tracked

npm, PyPI, Bundler, Cargo, container registries.

Pipelines

CI workflows and the steps that publish your deps.

Real attack paths

The route an attacker takes. Not a list of CVEs. The path to reach you.

The upstream attack surface.
Visible, finally.

Depi maps every dependency, maintainer, and pipeline between you and a supply chain compromise.

Trusted by security researchers and engineering leaders.

Keith Hoodlet

Director of Security Research of 1Password

I can count on one hand the number of times in my career where I looked at a security product and thought: “Wow!” 🤯

It happened again today when I sat down with Roni Carta to talk about what they’re building at Depi 🙌

Justin Gardner

Security Researcher and Top 50 HackerOne All Time

Depi was built by skilled hackers who uncovered real vulnerabilities and developed an effective tool that makes the difference in the Software Supply Chain.

Marten Mickos

Former CEO of HackerOne

Modern adversaries target complex software ecosystems. Created by ethical hackers who have seen more real-world vulnerabilities than most, Depi combines rigorous research and real-world offensive tactics to give you the upper hand. It’s an innovative leap for supply chain security.

Dominic Couture

Principal Security Engineer

Many supply chain security vendors make bold claims but few products deliver as much value as Depi. It’s powered by cutting-edge research by some of the best minds in the industry and will save you a lot of time and money with the issues it will detect before the bad actors do.

Adnan Khan

Software Supply Chain Researcher

Depi is built by battle-tested hackers who frequently identify complex, real world issues. This focus on real risks that can actually cause impact is what sets Depi apart.

Most of your software is built by people you've never met.

The way software gets built changed. The way it gets attacked changed with it. Here's the shift, and where Depi fits.

You don't write most of your software anymore.

A modern app is thousands of open-source packages, pulled from public registries, built and published by maintainers you'll never meet, through pipelines you don't control. You ship all of it. You trust all of it.

2,400+dependencies
900+maintainers

Attackers stopped breaking into your code.

They go upstream instead. A hijacked maintainer account. A poisoned build step. A package one level deeper than anyone looks. Then they let your own build ship the backdoor for them.

Your tools were never built to look there.

Scanners read the code you wrote and the packages you list. The compromise happens above that line, in the trust between you and everything that built your software. Nothing maps it.

Depi maps the whole chain.

Every package, pipeline, registry, and maintainer between a keyboard and your production build. We trace the trust, find the exploitable path, and bring you the fix, before it ever reaches you.

Five surfaces.
One graph underneath.

The same upstream graph, exposed to whoever needs it. CISOs read posture. AppSec works the queue. Developers merge the patch.

CISO
Head of AppSec

Risk posture across all projects at a glance.

Scores, trends, top exploits. The view a security leader keeps open in a tab, exposure changing in the right direction or the wrong one.

DevSecOps engineer

Full upstream map for a project.

Every node from manifest to maintainer. Flagged exploit paths shown in red, click any edge to see the trust relationship that makes it dangerous.

AppSec engineer

Triaged exploit list, ranked by impact on you.

Severity plus client-specific blast radius, not raw CVSS. Filter by exploit class, project, or ecosystem. The queue you actually work from.

Developer

The fix inbox. A dating app for your patches.

For every finding, Depi generates a candidate patch and brings it to you. It's a match, it's not, or ask for a different one. The ones you like ship themselves. Ten minutes a week, your queue stays clean.

Head of AppSec

When an incident drops, you already know if it matters.

See exactly which projects are exposed, how deep the path runs, and what auto-remediation is already queued. Within minutes of the public advisory.

Built on real findings.
Not theoretical threat models.

Depi started as a side project for finding bugs we kept hitting on engagements. Then the bugs got bigger. Here are three.

  • Security Research
    GitHub Actions

    Find Comment, Get Shell: Command Injection in dbt’s GitHub Actions

    An attacker-posted issue comment raced dbt automation and landed in a Bash conditional, leaking FISHTOWN_BOT_PAT. Exploit chain built by an AI agent.

    V.M.
    Read the research
  • Security Research
    npm

    npx Used Confusion and It’s Super Effective

    npx installs an unclaimed package when a bin name does not resolve locally. Claiming those names on the public registry earned five-figure RCE bounties.

    V.M.
    Read the research
  • Threat Intelligence
    npm

    node-ipc Compromised: A Dormant Maintainer, an Expired Domain, and What We Think Happened

    node-ipc 12.0.1 shipped a DNS-exfiltrating infostealer, published by a maintainer dormant 1,476 days whose contact domain had lapsed and been re-registered.

    RONI CARTA | LUPIN
    Read the research

No agents. No code changes.
GitHub App or GitLab OAuth. Running in minutes.

GitLabGitHubGitHub ActionsnpmPyPIRubyGemscrates.ioAWSMaven
Read the install guide

From the research.

One incident, end to end: the TanStack npm worm of May 2026, found by the same techniques and pattern library that ship inside Depi.

25days
Ahead of the attack. Depi had the whole chain mapped before a single malicious version was published.
47+packages
Backdoored across @tanstack, @uipath and adjacent scopes, every one of them carrying valid SLSA provenance.
6minutes
To publish ten malicious @tanstack versions once the worm had harvested npm tokens from a CI job.

The next incident is already in your upstream chain.

30 minutes with our team. Bring your most critical repo and we'll show you what's hiding in its upstream security, live, on the call, before you sign anything.