Semgrep Supply Chain’s new Dependency Graph empowers AppSec engineers to secure their software with greater efficiency. By combining the new Dependency path visualization and an enhanced lockfile workflow, it eliminates blind spots, reduces manual research, and speeds up prioritization and remediation.
The Dependency path visualization maps all dependencies—direct and transitive—showing exactly where vulnerabilities exist, even across multiple layers and paths. For package managers without standardized lockfiles like Maven and Gradle (what is covered in this product update), Semgrep reconstructs dependency trees to surface vulnerabilities.
These updates make onboarding and scanning repositories faster and more adaptable, regardless of workflow. Dependency Graphs are now in beta— please reference our announcement blog post for more details.