Every advisory
is a crime scene.
The package was clean yesterday. Today it's shipping to production. Depi works the case, who changed it, how it reaches you, and how to shut it down, before the trail goes cold.
Anyone can take the tip.
Depi works the case.
A public advisory is an anonymous tip, loud, vague, the same for everyone. Depi turns it into a dossier on your software: who's exposed, how deep it runs, and what to do about it tonight.
150+ packages: TanStack npm supply chain compromise
Affected projects
| Project | Status |
|---|---|
my-project2/2 | Resolved |
| @tanstack/react-router | Resolved |
| @tanstack/history | Resolved |
| @tanstack/react-router-devtools | Ignored |
my-api1/1 | Resolved |
| @tanstack/react-router | Resolved |
my-data-pipeline1/1 | Resolved |
| @mistralai/mistralai | Resolved |
my-web2/2 | Resolved |
| @tanstack/react-router | Resolved |
| @tanstack/arktype-adapter | Resolved |
my-worker1/1 | Resolved |
| @tanstack/history | Resolved |
my-mobile-bff1 ignored | Ignored |
| @tanstack/eslint-plugin-router | Ignored |
Working the case.
The moment a signal lands, the investigation runs itself. No analyst pulling threads at 3 a.m., no spreadsheet, no waiting on the ecosystem to catch up.
Generate
Every finding comes with a candidate patch already written, pinned versions, scoped names, the smallest change that closes the path. Linked to the finding that triggered it.
Swipe
Open the inbox, ten minutes a week. Match the ones you want, pass the ones you don't, ask for a different mitigation when it's close but not right.
Ship
Matches open as PRs in GitHub or GitLab, respecting your branch protection and reviewers. CI runs, you merge. Nothing bypasses your process.
Every case has a clock.
The longer it runs, the colder the trail.
Everyone finds out eventually. The teams that contain it are the ones who already knew their exposure when the advisory dropped. Depi closes the gap before the clock even starts.
Maintainer takeover paths
Expired maintainer email domains, hijackable nameserver delegations, organisation and package takeovers, and maintainer credentials exposed in breach data.
Pipeline attack classes
The workflows that build and publish your dependencies, read for pwn requests, TOCTOU windows, cache and artifact poisoning, short-SHA pinning and script injection.
Registry confusion
Unclaimed package names, dependency, workspace, manifest and NPX confusion, freshly claimed names with no history, and packages already flagged malicious.


