Know what's moving upstream
before it moves on you.

Depi watches the registries, maintainers, and pipelines behind the packages you depend on. When something turns hostile upstream, you hear it from us, often days before it becomes a public advisory.

Intelligence from the layer
above your manifest.

Most threat feeds tell you about CVEs after they're public. Depi watches the upstream conditions that produce the next compromise, while it's still forming.

Maintainer takeover paths

Expired maintainer email domains, hijackable nameserver delegations, organisation and package takeovers, and maintainer credentials exposed in breach data.

Pipeline attack classes

The workflows that build and publish your dependencies, read for pwn requests, TOCTOU windows, cache and artifact poisoning, short-SHA pinning and script injection.

Registry confusion

Unclaimed package names, dependency, workspace, manifest and NPX confusion, freshly claimed names with no history, and packages already flagged malicious.

Scoped to your stack.
Ranked by what reaches you.

Not a global firehose. Every item is filtered to the ecosystems and packages in your dependency tree, and ranked by how directly it can land on you.

Each signal links straight into the Incident Response view, so the moment something escalates you already see the blast radius and the queued fix.

Severity
ThreatEcosystemReachStatus
Critical
Dependency Confusioninternal name unclaimed on the public registry
npm
4 projects
open
Critical
Github Action Pwn Requestpull_request_target · untrusted checkout · writable token
GitHub Actions
2 projects
open
Critical
Upstream Account Breachmaintainer credentials leaked · session reuse
PyPI
1 project
open
High
Email Takeovermaintainer domain expired · claimable · account takeover path
npm
3 projects
open
Medium
NS Takeovernameserver delegation hijackable · depth 4
crates.io
1 project
mitigated

The team that finds the bugs
builds the detectors.

Depi's threat intelligence isn't scraped from public sources, and nobody is hand-feeding it. The research team that disclosed the npm cache-poisoning and email-domain-takeover classes turns each class into a detector, and the engine runs every one of them against your tree continuously.

Book a demo

See the next compromise coming from upstream.

Book a demo and we'll show you the live feed scoped to your real dependency tree.