Semgrep Product Update

Trace a vulnerable dependency's path straight from the CLI

Dependency path shows how a vulnerable package reached your project, tracing the chain from your app to the direct dependency to the transitive one, so teams can prioritize and remediate faster. That view has been available in the app and the API, but teams that consume Supply Chain results directly from the CLI had no way to see it there. Semgrep 1.168 adds the --x-dependency-paths flag, so CLI users now get dependency paths alongside any reported vulnerabilities.

profile image
Pablo Estrada