Review agent · Infra & pipeline

Supply chain

Checks dependency and build-time trust: pinning, lockfiles, registries and remote code.

Dockerfile1RUN pip install requests2RUN curl -sL get.tool.sh | sh3COPY . /appSupplywhat this review answersUnpinned deps or no lockfile?Integrity hashes present?Build steps running remote code?$ verdict REAL ISSUE$ fix pin with hashes, commit a lockfile▍

Illustrative example of how this agent reviews a finding.

Why this agent matters

You ship your dependencies' code as your own. Dependency confusion (2021), the event-stream npm compromise (2018) and SolarWinds all exploited trust in the build chain.

This agent reviews how dependencies are sourced and pinned. It does not yet look up CVEs in packages — software composition analysis is on our roadmap.

What it checks

  • Unpinned dependencies and missing lockfiles
  • Missing integrity hashes
  • Installs from untrusted sources or registries
  • Build steps that fetch and run remote code

When it marks a finding as a likely false positive

  • Versions are pinned with a lockfile and integrity hashes
  • Registries are restricted

The fix it suggests

  • Pinning versions with integrity hashes
  • Committing a lockfile
  • Restricting package registries

Scope and limits

This agent validates findings reported by Semgrep, Gitleaks and Trivy; it doesn't hunt for new bugs on its own. A finding reaches it when its CWE or rule/path keywords match this vulnerability class. It sees only the minimal code around the finding, with secrets redacted, and returns a verdict with a confidence score, a plain-English explanation and a suggested patch.

Common questions

Does this agent check for vulnerable package versions (CVEs)?

Not yet. It reviews supply-chain hygiene. Dependency CVE scanning via OSV is planned for a later phase.

Related agents

  • Infrastructure & IaC — Reviews Terraform, Helm, Ansible and server config for insecure defaults and exposure.
  • Cloud security — Checks cloud resources for public exposure, wildcard IAM and long-lived keys.
  • Container & Kubernetes — Checks Dockerfiles and Kubernetes manifests for root, privileged and host-level access.

See all 20 review agents → · Agent setup reviewer · How the pipeline works

Run the Supply chain agent on your repository

100 free credits, no credit card. Every finding comes with a verdict and a fix.

Get started free