securityfeature
Security that travels with your dependencies
The Impact Team·August 22, 2026
Every Impact scan runs deep security analysis (thousands of Semgrep rules across OWASP, CWE Top-25, and more) — not a fast lint. That's on by default, every scan.
But most real exposure isn't in your code — it's in your dependencies. So Impact reads your lockfiles and flags known CVEs in the exact versions you ship, plus incompatible or risky licenses. The Security pillar and the dependency view surface both, so "are we exposed?" has one honest answer that covers your code and everything it pulls in.
Vulnerable dependency, critical severity, in a version you're actually running — that's the finding that matters, and it's right on the dashboard.
Want to see this on your own codebase?
Analyze a repo free