Overview / Description
depgaze is an AI security tool that vets software dependencies by watching how they behave during installation, making it the best AI for catching supply-chain attacks before code reaches production. Rather than scanning source, it installs each package in a disposable sandbox with no host access and monitors OS-level activity: process spawns, file writes, and network connections. That behavioral view is what lets it flag malicious, abandoned, or typo-squatted packages and even zero-day threats at install time, before they land in a build. It plugs into CI/CD as a simple CLI with pass/fail exit codes, so a compromised dependency can break the pipeline automatically. Analysis is LLM-powered and works with existing providers including OpenAI, Anthropic, and AWS Bedrock, and depgaze can be called directly by AI coding agents such as Claude Code and Codex to vet dependencies as they are added. It runs locally on Linux or remotely with Windows support, and every plan includes unlimited seats and usage. For BestAIFor readers on engineering teams, depgaze is aimed at sitting alongside existing vulnerability scanners to add runtime, install-time behavioral detection. Pricing is published and annual, starting at EUR 5,000 per year.
Used For
Vetting open-source dependencies at install time to block supply-chain attacks, typo-squatting, and zero-day threats in CI/CD pipelines.
Pricing
Basic
€5,000/year (+VAT) — CLI, npm/PyPI support, offline support, unlimited seats and usage
Pros & Cons
Pros
- OS-level behavioral monitoring captures process spawns, file writes, and network connections during install
- Each package installs in a disposable sandbox with no host access
- CI/CD-native CLI with pass/fail exit codes to break pipelines on risky dependencies
- LLM analysis works with OpenAI, Anthropic, and AWS Bedrock, and is callable by Claude Code and Codex
- All plans include unlimited seats and usage
Cons
- Pricing starts at EUR 5,000/year, steep for individuals or small teams
- Local execution is Linux-only, with Windows available via the remote platform
- Install-time behavioral analysis adds time to the dependency workflow
- Requires bringing your own LLM provider for the analysis step
Questions & Answers
Alternatives
Socket, Snyk, Phylum
Reviews & Ratings
0 reviews
Sign in to rate and review depgaze.
Sign in to reviewNo reviews yet. Be the first to review depgaze!