Dependencies Engine
Comprehensive dependency vulnerability scanning with CVE tracking, license compliance, and automated remediation across all major package ecosystems.
Overview
The Dependencies Engine scans your project's dependency tree to identify known vulnerabilities (CVEs), outdated packages, and license compliance issues. It goes beyond direct dependencies to analyze the entire transitive dependency graph.
Why Dependencies Matter
Vulnerability Databases
Bloodhound aggregates vulnerability data from multiple authoritative sources for comprehensive coverage.
NVD (NIST)
Real-timeGitHub Advisory
Real-timeOSV Database
HourlySnyk Intel
DailyDependency Resolution
The engine supports all major package ecosystems with native lockfile parsing for accurate version resolution.
Transitive Dependencies
Most vulnerabilities hide in transitive (indirect) dependencies. Bloodhound traces the complete dependency graph to find them.
Dependency Path Analysis
Phantom Dependencies
License Compliance
Beyond security, the engine tracks open source licenses to ensure compliance with your organization's policies.
Auto-Remediation
Bloodhound can automatically fix vulnerable dependencies by updating to patched versions while maintaining compatibility.