Legit Security extends automated fixes to vulnerable open-source dependencies
Legit Security now uses its agent to patch vulnerable open-source dependencies and open verified pull requests.
Legit Security expanded Agentic Remediation from first-party static-analysis findings to vulnerabilities in open-source dependencies, including transitive packages. The agent identifies the vulnerable package, applies the smallest upgrade that stays in the current major version when possible, updates the lockfile, and re-scans before opening a pull request. When a fix requires a major-version jump, an AI layer proposes repository-specific code adaptations, which the company says are assessed rather than independently verified and are flagged in the pull request.
28