Find Comment, Get Shell: Command Injection in dbt’s GitHub Actions
An attacker-posted issue comment raced dbt automation and landed in a Bash conditional, leaking FISHTOWN_BOT_PAT. Exploit chain built by an AI agent.
Healthy upstream
Verified source · trusted flow
Risky upstream
Backdoored package · compromised repo
Maintainers
The humans whose keys could ship the next version.
Dependencies
Verified source · trusted flow
Registries
Provenance, tracked
npm, PyPI, Bundler, Cargo, container registries.
Pipelines
CI workflows and the steps that publish your deps.
Real attack paths
The route an attacker takes. Not a list of CVEs. The path to reach you.
Depi maps every dependency, maintainer, and pipeline between you and a supply chain compromise.

Keith Hoodlet
Director of Security Research of 1Password
I can count on one hand the number of times in my career where I looked at a security product and thought: “Wow!” 🤯
It happened again today when I sat down with Roni Carta to talk about what they’re building at Depi 🙌

Justin Gardner
Security Researcher and Top 50 HackerOne All Time
Depi was built by skilled hackers who uncovered real vulnerabilities and developed an effective tool that makes the difference in the Software Supply Chain.

Marten Mickos
Former CEO of HackerOne
Modern adversaries target complex software ecosystems. Created by ethical hackers who have seen more real-world vulnerabilities than most, Depi combines rigorous research and real-world offensive tactics to give you the upper hand. It’s an innovative leap for supply chain security.

Dominic Couture
Principal Security Engineer
Many supply chain security vendors make bold claims but few products deliver as much value as Depi. It’s powered by cutting-edge research by some of the best minds in the industry and will save you a lot of time and money with the issues it will detect before the bad actors do.

Adnan Khan
Software Supply Chain Researcher
Depi is built by battle-tested hackers who frequently identify complex, real world issues. This focus on real risks that can actually cause impact is what sets Depi apart.
The way software gets built changed. The way it gets attacked changed with it. Here's the shift, and where Depi fits.
A modern app is thousands of open-source packages, pulled from public registries, built and published by maintainers you'll never meet, through pipelines you don't control. You ship all of it. You trust all of it.
They go upstream instead. A hijacked maintainer account. A poisoned build step. A package one level deeper than anyone looks. Then they let your own build ship the backdoor for them.
Scanners read the code you wrote and the packages you list. The compromise happens above that line, in the trust between you and everything that built your software. Nothing maps it.
Every package, pipeline, registry, and maintainer between a keyboard and your production build. We trace the trust, find the exploitable path, and bring you the fix, before it ever reaches you.
The same upstream graph, exposed to whoever needs it. CISOs read posture. AppSec works the queue. Developers merge the patch.
Scores, trends, top exploits. The view a security leader keeps open in a tab, exposure changing in the right direction or the wrong one.
Every node from manifest to maintainer. Flagged exploit paths shown in red, click any edge to see the trust relationship that makes it dangerous.
Severity plus client-specific blast radius, not raw CVSS. Filter by exploit class, project, or ecosystem. The queue you actually work from.
For every finding, Depi generates a candidate patch and brings it to you. It's a match, it's not, or ask for a different one. The ones you like ship themselves. Ten minutes a week, your queue stays clean.
See exactly which projects are exposed, how deep the path runs, and what auto-remediation is already queued. Within minutes of the public advisory.
Depi started as a side project for finding bugs we kept hitting on engagements. Then the bugs got bigger. Here are three.
An attacker-posted issue comment raced dbt automation and landed in a Bash conditional, leaking FISHTOWN_BOT_PAT. Exploit chain built by an AI agent.
npx installs an unclaimed package when a bin name does not resolve locally. Claiming those names on the public registry earned five-figure RCE bounties.
node-ipc 12.0.1 shipped a DNS-exfiltrating infostealer, published by a maintainer dormant 1,476 days whose contact domain had lapsed and been re-registered.
One incident, end to end: the TanStack npm worm of May 2026, found by the same techniques and pattern library that ship inside Depi.
30 minutes with our team. Bring your most critical repo and we'll show you what's hiding in its upstream security, live, on the call, before you sign anything.