{"id":5192,"date":"2026-09-30T15:07:09","date_gmt":"2026-09-30T15:07:09","guid":{"rendered":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/2026\/09\/30\/legit-security-launches-agentic-remediation-for-open-source-dependency-vulnerabilities\/"},"modified":"2026-09-30T15:07:09","modified_gmt":"2026-09-30T15:07:09","slug":"legit-security-launches-agentic-remediation-for-open-source-dependency-vulnerabilities","status":"publish","type":"post","link":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/2026\/09\/30\/legit-security-launches-agentic-remediation-for-open-source-dependency-vulnerabilities\/","title":{"rendered":"Legit Security launches agentic remediation for open-source dependency vulnerabilities"},"content":{"rendered":"<div><img data-opt-id=1424880622  fetchpriority=\"high\" decoding=\"async\" width=\"1280\" height=\"993\" src=\"https:\/\/devops.com\/wp-content\/uploads\/2026\/09\/2026-09-30_173053_1790778913wrJa2BRyLR.jpg\" class=\"attachment-large size-large wp-post-image\" alt=\"\" \/><\/div>\n<p><img data-opt-id=94368018  fetchpriority=\"high\" decoding=\"async\" width=\"150\" height=\"150\" src=\"https:\/\/devops.com\/wp-content\/uploads\/2026\/09\/2026-09-30_173053_1790778913wrJa2BRyLR-150x150.jpg\" class=\"attachment-thumbnail size-thumbnail wp-post-image\" alt=\"\" \/><\/p>\n<p class=\"sc-lpcdUm dHRSsU\"><span><strong>Tel Aviv, Israel, September 30th, 2026, CyberNewswire<\/strong><\/span><\/p>\n\n<p><a target=\"_blank\" rel=\"nofollow noopener\" href=\"https:\/\/www.legitsecurity.com\/\">Legit Security<\/a> today announced an expansion of its Agentic Remediation capability to cover vulnerabilities found in open-source dependencies, not just first-party code \u2013 enabling development teams to move from vulnerability detection to a verified fix without manual triage.<\/p>\n<p>The expansion addresses a growing gap in application security: as AI-generated code accelerates software delivery, most modern codebases are made up largely of open-source dependencies, and every new package introduces potential exposure to known vulnerabilities. Traditional find-it, fix-it AppSec workflows, which rely on human teams working down a backlog, can\u2019t keep pace with that volume \u2013 particularly when the vulnerable code isn\u2019t in a company\u2019s own codebase but several layers deep in a third-party package.<\/p>\n<p><a target=\"_blank\" rel=\"nofollow noopener\" href=\"https:\/\/www.legitsecurity.com\/ai-powered-remediation-fix-appsec-issues-faster-with-legit\">Legit\u2019s Agentic Remediation<\/a> previously focused on fixing static analysis findings in code written by a company\u2019s own engineers. With this release, the same agent now takes on <a target=\"_blank\" rel=\"nofollow noopener\" href=\"https:\/\/info.legitsecurity.com\/hubfs\/Legit%20Root%20Cause%20Remediation-03.10.25-1.pdf\">vulnerabilities introduced through dependencies<\/a>, extending verified remediation to the other major source of vulnerabilities in modern software.<\/p>\n<blockquote>\n<p>\u201cThe real challenge isn\u2019t finding vulnerabilities anymore \u2013 it\u2019s getting from finding to fix fast enough,\u201d the company said, noting that AI-generated code has multiplied the volume of software shipping daily while attackers increasingly use AI to find and exploit those vulnerabilities faster than defenders can respond.<\/p>\n<\/blockquote>\n<p><strong>How it works<\/strong><\/p>\n<p>When pointed at a vulnerable dependency, the agent:<\/p>\n<ul>\n<li>Identifies the dependency \u2013 the vulnerable package, its current version, and whether it\u2019s a direct or indirect (transitive) dependency.<\/li>\n<li>Finds the safest upgrade \u2013 the smallest version bump that resolves the issue, staying within the current major version where possible to avoid breaking changes.<\/li>\n<li>Applies the fix \u2013 updates the dependency configuration and regenerates the lockfile, including any other instances of the vulnerable version elsewhere in the dependency tree.<\/li>\n<li>Verifies the fix \u2013 re-scans the dependency before and after the change to confirm the vulnerability is resolved and no new issue was introduced.<\/li>\n<li>Opens a pull request \u2013 delivering a ready-to-review PR with the fix and vulnerability details attached.<\/li>\n<\/ul>\n<p>Every fix is re-scanned before a PR is opened, so developers receive a change that has already been verified rather than a suggested version to try.<\/p>\n<p><strong>Handling major version upgrades<\/strong><\/p>\n<p>When a fix requires crossing a major version boundary \u2013 where breaking API changes become a risk \u2013 the agent adds an AI-assisted analysis layer that evaluates how the specific repository uses the package and proposes the source code adaptations needed, validated against the real repository and package data.<\/p>\n<p>Legit draws a clear distinction in these cases: the dependency fix itself is verified through re-scanning, like any other remediation, while the code adaptation for a major version jump is AI-assessed rather than independently verified. The company said the PR flags this distinction explicitly, so developers know what\u2019s been verified and what warrants closer review before merging.<\/p>\n<p><strong>About Legit Security<\/strong><\/p>\n<p>Legit positions the expansion as part of a broader effort to close the gap between detection and a safe, verified fix across both first-party code and open-source dependencies \u2013 the two primary sources of vulnerabilities in modern software \u2013 without relying on manual backlog triage.<\/p>\n<h5>Contact<\/h5>\n<p><span><strong>Dave Howell<\/strong><br \/><\/span><span><strong>Legit Security<\/strong><br \/><\/span><span><strong>dave@legitsecurity.com<\/strong><br \/><\/span><\/p>\n<p><a href=\"https:\/\/devops.com\/legit-security-launches-agentic-remediation-for-open-source-dependency-vulnerabilities\/\" target=\"_blank\" class=\"feedzy-rss-link-icon\">Read More<\/a><\/p>\n<p>\u200b<\/p>","protected":false},"excerpt":{"rendered":"<p>Tel Aviv, Israel, September 30th, 2026, CyberNewswire Legit Security today announced an expansion of its Agentic Remediation capability to cover [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":5193,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[5],"tags":[],"class_list":["post-5192","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-devops"],"_links":{"self":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts\/5192","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/comments?post=5192"}],"version-history":[{"count":0,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts\/5192\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/media\/5193"}],"wp:attachment":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/media?parent=5192"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/categories?post=5192"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/tags?post=5192"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}