Recommended Free Tools
Legit Security says its Agentic Remediation capability can now address vulnerabilities in open-source dependencies as well as static-analysis findings in first-party code. The announced workflow identifies affected direct and transitive packages, proposes a targeted upgrade, updates dependency files, rescans the change and opens a pull request for human review. A major-version upgrade adds an important distinction: the dependency fix is rescanned, but suggested source-code adaptations are AI-assessed rather than independently verified.
What Legit Security announced
Legit Security announced an expansion of Agentic Remediation to include vulnerable open-source dependencies. The announcement was distributed by Technology Newswire and published by TechCrunch on September 30, 2026; Help Net Security covered it on October 1, 2026. The TechCrunch item is a vendor announcement distributed through a newswire, not independent product testing. TechCrunch · Help Net Security
The company frames the change as a way to move from identifying a vulnerable package to preparing a proposed code change. It says the agent determines the package and installed version, checks whether the dependency is direct or transitive, and seeks the smallest upgrade that resolves the issue while staying within the current major version where possible. It then updates dependency configuration, regenerates the lockfile, and addresses other instances of the vulnerable version in the dependency tree.
How the announced remediation workflow works
- Identify the dependency: The agent identifies the vulnerable package and current version, including whether it is a direct or transitive dependency.
- Select an upgrade: It seeks the smallest version change that resolves the vulnerability, preferring an upgrade within the existing major version where possible.
- Update project files: It changes dependency configuration and regenerates the lockfile, including other occurrences of the vulnerable version in the tree.
- Rescan and propose the change: Legit says it rescans before and after the change, then opens a pull request containing the fix and vulnerability details for review.
Legit describes the rescan as verification. That term applies to the vendor’s stated scanning process; the announcement does not provide independent efficacy testing, false-positive rates or customer outcome data.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problems#1 Best Overall
What changes when an upgrade crosses a major version
A major-version upgrade can require source changes because a newer release may alter or remove APIs used by the application. Legit says that when its proposed fix crosses a major-version boundary, the agent analyzes how the repository uses the package and proposes AI-assisted source-code adaptations.
The distinction matters for review: the dependency change is rescanned, while the accompanying source-code adaptation is AI-assessed, not independently verified. The company says the pull request marks that difference so reviewers can give the adaptation closer attention. Teams should therefore review and test the proposed code changes rather than treating the rescan as confirmation that the entire major-version migration is correct.
Rank #2
What the announcement does not establish
The announcement and follow-up coverage do not specify which ecosystems, manifests, integrations or customer plans the expanded capability supports, or when it will be available to particular customers. They also do not report comparative performance, customer results, pricing or independent testing. Those details should be confirmed with Legit Security before evaluating availability or fit.
The company summarized the problem it is targeting this way: “The real challenge isn’t finding vulnerabilities anymore – it’s getting from finding to fix fast enough,” the announcement distributed by Technology Newswire.
How this fits alongside other dependency-remediation tools
Legit Security is not the only project describing automated dependency remediation. In an April 2, 2024 post, Google’s Open Source Security Team described guided remediation in the separate, open-source OSV-Scanner. Google said that, at the time, guided remediation could automatically upgrade dependencies and supported npm package.json and package-lock.json. The same post described OSV-Scanner support for 11 language ecosystems and 19 lockfile formats; those figures refer to Google’s tool as described in 2024, not to Legit Security. Google also discussed interactive prioritization using factors such as severity, dependency depth and dependency type, as well as CI/CD scanning and reachability analysis intended to reduce false positives. Google Open Source Security Team
The available descriptions do not provide comparative performance data, so they do not support a claim that one tool is more accurate or effective. For a practical evaluation, compare:
Quick Recap
Rank #4
- Supported language ecosystems, manifests and lockfile formats.
- Whether direct and transitive dependencies are handled.
- How the tool selects upgrades and handles major-version changes.
- Whether it edits manifests and regenerates lockfiles.
- What rescanning or other verification is performed, and which changes remain AI-assessed.
- How proposed fixes reach developers, and what testing and human review are required.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




