Which vulnerable dependency should you fix first?
npm audit or a Dependabot list can show 40 advisories for 7 packages, with no order. Depmoor reads your lockfile in the browser, looks up every pinned package in OSV.dev, then ranks the findings: fix now (in CISA KEV, or EPSS of 10% or more), fix soon, or plan. It merges duplicate advisories and gives one upgrade per package, including a same-major option where one exists.
Three sample lockfiles with old pins (Depmoor, 1 Oct 2026)
| Lockfile | Packages | Findings | Fix now | In CISA KEV |
|---|---|---|---|---|
| gradle.lockfile (log4j 2.14.1, Spring 5.3.17, …) | 7 | 40 | 9 | 4 (CVE-2021-44228, CVE-2021-45046, CVE-2022-22965 x2) |
| requirements.txt (Django 3.2.0, Pillow 8.0.0, …) | 7 | 104 | 10 | 1 (CVE-2023-4863, libwebp in Pillow) |
| package-lock.json (axios 0.21.0, express 4.17.1, …) | 9 | 46 | 2 | 0 |
Source: Depmoor scans of its built-in samples, 1 Oct 2026 (OSV.dev live, CISA KEV 2026.09.30, FIRST EPSS 2026-09-29). Try the same samples free in the app.
Depmoor vs the alternatives
Published prices, each checked on the date shown; prices change, so confirm on each site.
| Product | Price | Free | Checked |
|---|---|---|---|
| Depmoor Pro | $9/month or $90/year; Team $29/month | 5 scans a day | live |
| Vulert | Pro $15 per monitored app/month; Growth $25 | - | 2026-10-01 |
| Socket | Team $25 per developer/month (minimum 5 developers) | free plan | 2026-10-01 |
| Debricked | Premium $25 per contributing developer/month | free plan | 2026-10-01 |
Why teams pick Depmoor
- Ranked by what attackers do: a Java lockfile with 40 findings comes down to 9 'fix now', 4 of them in CISA KEV (Log4Shell, CVE-2021-45046, Spring4Shell).
- 13 lockfile formats: npm, yarn, pnpm, pip requirements, poetry, uv, Pipfile, Cargo, Go, Composer, Bundler, Gradle and NuGet.
- The lockfile is parsed in your browser; only package names and versions go to OSV.dev.
- $9/month for unlimited scans, against $15 per app at Vulert or $25 per developer at Socket and Debricked.
How it works
- Open Depmoor and drop your lockfile (or press a sample).
- Read the 'Fix now' tiles first: those are exploited or likely to be.
- Apply the upgrade plan: one target version per package, with a same-major option when one clears most findings.
- With Pro, export SARIF for GitHub/GitLab code scanning or gate CI with fail_on=fix-now.
FAQ
Which vulnerable dependency should I fix first?
The ones in CISA's Known Exploited Vulnerabilities catalog, then those with a high EPSS (likely to be exploited soon), then critical/high severity. Depmoor sorts every finding into fix now, fix soon and plan on exactly that basis.
Is my lockfile uploaded?
No. It is parsed in your browser; only package names and versions are sent to OSV.dev to look up advisories.
How is this different from npm audit?
npm audit lists advisories by severity for npm only. Depmoor covers 13 lockfile formats, merges duplicate advisories and ranks by real exploitation, with one upgrade per package.
Can it fail my CI build?
Yes, with Pro or Team: POST the lockfile to the CI API with fail_on=fix-now and the call returns HTTP 422 when something needs fixing now.