All posts
securityfeature

Security that travels with your dependencies

The Impact Team·August 22, 2026

Every Impact scan runs deep security analysis (thousands of Semgrep rules across OWASP, CWE Top-25, and more) — not a fast lint. That's on by default, every scan.

But most real exposure isn't in your code — it's in your dependencies. So Impact reads your lockfiles and flags known CVEs in the exact versions you ship, plus incompatible or risky licenses. The Security pillar and the dependency view surface both, so "are we exposed?" has one honest answer that covers your code and everything it pulls in.

Vulnerable dependency, critical severity, in a version you're actually running — that's the finding that matters, and it's right on the dashboard.

Want to see this on your own codebase?

Analyze a repo free
Security that travels with your dependencies