SaaSActive

DeepSource Vulnerability Scanning

DeepSource's vulnerability scanning feature detects known vulnerabilities in dependencies across multiple languages.

Open source page

Product features

Product features

Autofix Pull Requests

Automatically creates pull requests to update vulnerable dependencies to secure versions.

Continuous Monitoring

Continuously monitors dependencies for new vulnerabilities and reports them in the dashboard.

CVE Identification

Provides CVE identifier and description for each vulnerability.

Dynamic Risk Score

Provides a dynamic risk score to help prioritize fixing.

Language Support

Supports Python, Go, JavaScript, Java, Ruby, Rust, Kotlin, C#, and PHP.

Lockfile Generation

Can generate lockfiles for C# projects using dotnet restore or nuget restore.

Manual Target Add

Reachability Analysis

Indicates whether vulnerable code is called by your application.

Severity Metrics

Shows CVSS and EPSS scores for each vulnerability.

Target Sync

Discovers and syncs all manifest files in the repository.

Vulnerability Detection

Detects security vulnerabilities in code during analysis.