Legit Security AI agent now fixes open-source dependencies
Legit Security has expanded its Agentic Remediation feature so it now handles vulnerabilities in open-source dependencies, not only in code that a company writes itself. The goal is to take development teams from a vulnerability finding to a verified fix without anyone having to triage the issue by hand.
Until now, the agent worked on static analysis findings in first-party code, meaning code written by a company's own engineers. The new release points the same agent at packages pulled in from outside, which the company describes as the other major source of vulnerabilities in modern software.
A volume problem
Legit Security frames the update as a response to a widening gap in application security (AppSec). AI-generated code is speeding up software delivery, and most modern codebases now consist largely of open-source dependencies. Each new package can bring known vulnerabilities with it.
The classic AppSec workflow, where human teams work through a backlog of findings one by one, struggles with that volume. It gets harder when the flawed code is not in the company's own repository but buried several layers down inside a third-party package.
"The real challenge isn't finding vulnerabilities anymore - it's getting from finding to fix fast enough," the company said. It added that AI-generated code has multiplied the amount of software shipped every day, while attackers increasingly use AI to find and exploit flaws faster than defenders can react. That concern matches a broader trend of AI speeding up exploitation that security teams have been tracking.
Five steps to a pull request
When the agent is given a vulnerable dependency, it goes through a fixed sequence:
- Identify the affected package, its current version, and whether it is a direct dependency or a transitive one pulled in by another package.
- Pick the safest upgrade, which is the smallest version bump that resolves the issue. Where possible, it stays within the current major version to avoid breaking changes.
- Apply the fix by updating the dependency configuration and regenerating the lockfile. This also covers other instances of the vulnerable version elsewhere in the dependency tree.
- Verify the result by scanning the dependency before and after the change. The check confirms the flaw is gone and that no new issue has appeared.
- Open a pull request that is ready for review, with the fix and the vulnerability details attached.
Because every fix is re-scanned before the PR is created, developers get a change that has already been checked, rather than a suggested version they still need to test themselves.
When a major version jump is needed
Some fixes only exist in a newer major version, where breaking API changes become a real risk. In those cases, the agent adds an AI-assisted analysis step. It looks at how the specific repository uses the package and proposes the source code changes needed to adapt. These proposals are validated against the actual repository and package data.
Legit Security draws a clear line between the two parts of such a fix. The dependency upgrade itself is verified by re-scanning, like every other remediation. The code adaptation for the major version jump, however, is assessed by AI and not independently verified. According to the company, the PR states this distinction explicitly, so developers can see what has been confirmed and what needs a closer look before merging.
Our Take
This release fits a pattern we have seen across the industry in recent weeks: vendors are moving AI from spotting problems to actually fixing them. Google's Gemini 4 Argon finding and patching flaws and Sophos using AI to prioritize fixes point in the same direction.
For readers, the more interesting detail is Legit Security's own admission that AI-written code adaptations are not independently verified. This suggests the human review step is not going away, especially for major upgrades. Dependency risk also remains broader than outdated versions, as incidents like the OpenInfra Europe Artifactory breach show. It is worth watching whether teams trust these automated PRs enough to merge them quickly, and how often the AI-assessed changes hold up in production.
