Legit Security has announced an expansion of its Agentic Remediation capability to cover vulnerabilities in open-source dependencies, according to Help Net Security. Previously limited to static analysis findings in first-party code, the agent now handles third-party packages, including transitive dependencies. The company says the real challenge is no longer finding vulnerabilities but getting from finding to fix fast enough, particularly as AI-generated code increases the volume of software shipped and attackers use AI to exploit vulnerabilities faster.

When pointed at a vulnerable dependency, the agent identifies the package and its version, determines whether it is direct or transitive, and selects the smallest version bump that resolves the issue while staying within the current major version where possible. It then updates the dependency configuration, regenerates the lockfile, re-scans before and after the change, and opens a pull request with the fix and vulnerability details. The re-scan is intended to confirm that the vulnerability is resolved and no new issue was introduced.

For fixes that require crossing a major version boundary, the agent adds an AI-assisted analysis of how the repository uses the package and proposes source-code adaptations. The dependency fix itself is verified by re-scanning, while the code adaptation for the major version jump is AI-assessed rather than independently verified. Legit Security says the pull request flags this distinction explicitly so developers know what has been verified and what needs closer review before merging.