Threat Intelligence
Know what is moving upstream before it reaches you. Named attack classes, live maintainer and registry signals, and the research feed the detectors are built from.
Depi builds a live graph across 10 node types, projects, manifests, packages, maintainers, registries, email domains, GitHub repos, CI pipelines, attack vectors, and organisations. Every trust relationship in your upstream security, continuously re-evaluated.
Your real attack surface sits above the manifest.
They start in the pipeline that published your dependency. In the maintainer account taken over last Tuesday. In the build steps and registries your code never declares but always trusts. Depi maps all of it.
No agents. No code changes. A GitHub App or GitLab OAuth, and Depi starts walking your upstream security, every package, every pipeline, every maintainer.
One click. Read-only. GitHub or GitLab, live in minutes. No agents, no code changes.
Every link, mapped. Packages, pipelines, registries, and the people behind them. Your whole upstream, live.
Swipe. Match. Ship. Every finding comes with a patch ready to merge. Ten minutes a week.
Depi is not an SCA, not an SBOM generator, not a SAST, not a CNAPP and not a secret scanner. It does one thing, map and detect upstream supply-chain risk. Here is where each of those stops looking.
| Tool | Looks at | Misses | Depi adds |
|---|---|---|---|
SCA · Snyk, DependabotDependency scanning | Known vulnerabilities in your package list | Pipelines, registries, maintainers, undeclared build steps | Upstream chain + named attack classes + blast radius |
SBOM · FOSSA, Anchore, SyftInventory | Snapshot of package names and versions | Causation. Pipelines. Trust edges. | Live, dynamic SBOM with provenance and trust graph |
SAST · Semgrep, CodeQLCode analysis | Source code you wrote | The links around your dependencies, pipelines, maintainers, registries | The upstream surface an attacker would backdoor before code ever runs |
CNAPP · Wiz, OrcaCloud posture | Runtime risk in cloud workloads | How that workload's dependencies got built | Pre-runtime: the upstream security that produces what runs in the cloud |
Secret scanning · TruffleHogCredential detection | Hard-coded secrets in repos | Compromised maintainer credentials in registries | Maintainer trust signals at the publisher account |
Package-behavior scanning · SocketReactive triage | Each new dependency version, scanned after publish for malicious behavior | The upstream conditions that let a backdoor land in the first place | Proactive map of the maintainers, pipelines and registries that could ship a backdoor, before MTTD, not after |
Depi doesn't just enumerate packages. It walks every edge. The graph below is the real TanStack compromise of May 2026: a pull request reaches a pull_request_target workflow, the workflow leaks its cache credentials, the poisoned pnpm store is restored by the release pipeline, and 47+ packages ship backdoored with valid provenance. Depi mapped that chain 25 days before it was executed.
TanStack's own maintainers did nothing wrong. The compromise entered through a workflow trigger, which is why Depi treats pipelines as nodes and not as build detail.
SBOM tools enumerate names. Depi maps causation.
Same packages, completely different posture.
| Capability | Static SBOMFOSSA · ANCHORE · SYFT · OSS REVIEW | Depi dynamic SBOM |
|---|---|---|
Lists package names + versions | Yes, that's the entire output | Yes, with maintainer + pipeline provenance |
Snapshot vs continuous | Snapshot at scan time. Stale within hours. | Continuously re-evaluated. Re-graphs on every push and every upstream change. |
Maps the upstream chain | No, the chain stops at the package | Yes, manifest → registry → repo → pipeline → maintainer → domain |
Detects pipeline tampering | Silent. Pipelines aren't in the model. | GitHub Action Cache Poisoning, PWN Request, Artifact Poisoning, Short SHA |
Detects maintainer compromise | Silent. Maintainers aren't in the model. | Email domain expiry, nameserver hijack, org takeover, leaked maintainer credentials |
Findings ranked by | CVSS, global, ecosystem-level | Exploitability + your blast radius. Per-project depth. |
Output | JSON / SPDX / CycloneDX file | Live graph + ranked findings + auto-generated fix PRs |
The platform is one upstream graph. These are the three surfaces teams actually work from, each with its own page.
Know what is moving upstream before it reaches you. Named attack classes, live maintainer and registry signals, and the research feed the detectors are built from.
Every finding arrives as a candidate patch. Accept it, skip it, or ask for a different one. The ones you keep open their own PR and ship themselves.
When an advisory drops, the blast radius is already mapped to your tree. Which projects are exposed, how deep the path runs, and what remediation is queued.
Six package ecosystems and two source-control providers today. Coverage expands when researcher demand and customer demand line up.
Read-only by default. App preferred for org-wide scanning. OAuth for individual repo grants.
Self-hosted GitLab supported. Read-only project access. Audit log on every scan.
A 30-minute session, on the call, with a real graph of your real chain. No pre-sales filter. The team running the demo is the team that found the bugs.