Close Menu
Daily Guardian
  • Home
  • News
  • Politics
  • Business
  • Entertainment
  • Lifestyle
  • Health
  • Sports
  • Technology
  • Climate
  • Auto
  • Travel
  • Web Stories
What's On

Blazo Gjorev and Panteleon GS Co-Host BCIU Business Roundtable at The Yale Club in New York

September 30, 2026

Digital Twins in Defense: Lessons Learned, Emerging Opportunities and the Road Ahead

September 30, 2026

One Day Left: Nearly 185 Southern California Technology Leaders Registered for HMG Strategy's October 1 Summit on Enterprise AI, Cyber Resilience and Digital Transformation

September 30, 2026

Distraction thefts spiking in Peel, police say after woman robbed of $19K in jewelry

September 30, 2026

Blue Jays GM Atkins says ‘everything needs to be assessed’ after last-place finish

September 30, 2026
Facebook X (Twitter) Instagram
Finance Pro
Facebook X (Twitter) Instagram
Daily Guardian
Subscribe
  • Home
  • News
  • Politics
  • Business
  • Entertainment
  • Lifestyle
  • Health
  • Sports
  • Technology
  • Climate
  • Auto
  • Travel
  • Web Stories
Daily Guardian
Home » Legit Security launches agentic remediation for open-source dependency vulnerabilities
Press Release

Legit Security launches agentic remediation for open-source dependency vulnerabilities

By News RoomSeptember 30, 20263 Mins Read
Legit Security launches agentic remediation for open-source dependency vulnerabilities
Share
Facebook Twitter LinkedIn Pinterest Email

TEL AVIV, Israel, Sept. 30, 2026 (GLOBE NEWSWIRE) — Legit Security today announced an expansion of its Agentic Remediation capability to cover vulnerabilities found in open-source dependencies, not just first-party code – enabling development teams to move from vulnerability detection to a verified fix without manual triage.

The expansion addresses a growing gap in application security: as AI-generated code accelerates software delivery, most modern codebases are made up largely of open-source dependencies, and every new package introduces potential exposure to known vulnerabilities. Traditional find-it, fix-it AppSec workflows, which rely on human teams working down a backlog, can’t keep pace with that volume – particularly when the vulnerable code isn’t in a company’s own codebase but several layers deep in a third-party package.

Legit’s Agentic Remediation previously focused on fixing static analysis findings in code written by a company’s own engineers. With this release, the same agent now takes on vulnerabilities introduced through dependencies, extending verified remediation to the other major source of vulnerabilities in modern software.

“The real challenge isn’t finding vulnerabilities anymore – it’s getting from finding to fix fast enough,” the company said, noting that AI-generated code has multiplied the volume of software shipping daily while attackers increasingly use AI to find and exploit those vulnerabilities faster than defenders can respond.

How it works
When pointed at a vulnerable dependency, the agent:

  • Identifies the dependency – the vulnerable package, its current version, and whether it’s a direct or indirect (transitive) dependency.
  • Finds the safest upgrade – the smallest version bump that resolves the issue, staying within the current major version where possible to avoid breaking changes.
  • Applies the fix – updates the dependency configuration and regenerates the lockfile, including any other instances of the vulnerable version elsewhere in the dependency tree.
  • Verifies the fix – re-scans the dependency before and after the change to confirm the vulnerability is resolved and no new issue was introduced.
  • Opens a pull request – delivering a ready-to-review PR with the fix and vulnerability details attached.

Every fix is re-scanned before a PR is opened, so developers receive a change that has already been verified rather than a suggested version to try.

Handling major version upgrades
When a fix requires crossing a major version boundary – where breaking API changes become a risk – the agent adds an AI-assisted analysis layer that evaluates how the specific repository uses the package and proposes the source code adaptations needed, validated against the real repository and package data.

Legit draws a clear distinction in these cases: the dependency fix itself is verified through re-scanning, like any other remediation, while the code adaptation for a major version jump is AI-assessed rather than independently verified. The company said the PR flags this distinction explicitly, so developers know what’s been verified and what warrants closer review before merging.

About Legit Security
Legit positions the expansion as part of a broader effort to close the gap between detection and a safe, verified fix across both first-party code and open-source dependencies – the two primary sources of vulnerabilities in modern software – without relying on manual backlog triage.

Contact

Dave Howell
Legit Security
[email protected]

A photo accompanying this announcement is available at https://www.globenewswire.com/NewsRoom/AttachmentNg/28cd3d1a-2a60-432e-b742-e6363d79fcff

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Keep Reading

Blazo Gjorev and Panteleon GS Co-Host BCIU Business Roundtable at The Yale Club in New York

Digital Twins in Defense: Lessons Learned, Emerging Opportunities and the Road Ahead

One Day Left: Nearly 185 Southern California Technology Leaders Registered for HMG Strategy's October 1 Summit on Enterprise AI, Cyber Resilience and Digital Transformation

Fort Worth Stockyards Announces 2026 Holiday Lineup, Offering a Western Holiday Experience in Dallas-Fort Worth Nov. 17, 2026 – Jan. 3, 2027

ImageFIRST Opens Nationwide Voting for 6th Annual HeroesFIRST Contest

Norton Rose Fulbright appoints Luke Maher Partner-in-Charge of St. Louis office

Flame Diet App Launches Personalized Anti-Inflammatory Diet

RoadHitter: Redefine Off-Road Electric Scooter

UE Electronic Expands Medical and ITE Power Supply Portfolio with 240W GaN USB PD 3.2 Solution

Editors Picks

Digital Twins in Defense: Lessons Learned, Emerging Opportunities and the Road Ahead

September 30, 2026

One Day Left: Nearly 185 Southern California Technology Leaders Registered for HMG Strategy's October 1 Summit on Enterprise AI, Cyber Resilience and Digital Transformation

September 30, 2026

Distraction thefts spiking in Peel, police say after woman robbed of $19K in jewelry

September 30, 2026

Blue Jays GM Atkins says ‘everything needs to be assessed’ after last-place finish

September 30, 2026

Latest News

Fort Worth Stockyards Announces 2026 Holiday Lineup, Offering a Western Holiday Experience in Dallas-Fort Worth Nov. 17, 2026 – Jan. 3, 2027

September 30, 2026

The Halide camera app now offers full control of the iPhone 18 Pro’s aperture

September 30, 2026

ImageFIRST Opens Nationwide Voting for 6th Annual HeroesFIRST Contest

September 30, 2026
Facebook X (Twitter) Pinterest TikTok Instagram
© 2026 Daily Guardian Canada. All Rights Reserved.
  • Privacy Policy
  • Terms
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.

Go to mobile version