ThreatGraph scans GitHub repositories, matches dependencies to vulnerability intelligence, recommends safe upgrade versions, and creates GitHub issues automatically when a confident remediation exists.
Your team doesn't need more alerts. It needs remediation intelligence.
Scanners produce noise — teams drown in alerts with no clear actions.
Remediation research is manual and slow — "what version do I upgrade to?"
Dependency fixes stall because "what version?" isn't answered.
GitHub workflow integration is often shallow or bolt-on.
Every scan flows through a structured pipeline — deterministic first, AI only when needed.
Register repositories from your GitHub organization.
Ingestor parses manifests and lockfiles across all ecosystems.
Maps packages to GHSA, OSV, and NVD advisories in priority order.
Structured range matching against affected and patched version ranges.
Computes exact upgrade target with confidence scoring.
Auto-creates issues when confidence ≥ 90, with full rationale.
Every feature is designed to reduce time-to-remediation.
Not all vulnerabilities have fixes. See only what your team can act on — skip the noise.
"Upgrade lodash from 4.17.20 to 4.17.21 — confidence: 95." Specific, actionable, trustworthy.
Auto-create at 90+. Flag for review at 75–89. Skip below 75. You control the threshold.
Package-native advisory matching means less manual version research per vulnerability.
Confidence scoring and recommendation types create clear review signals. Humans decide, machines execute.
A single remediation pipeline serves both teams. No more ticketing bounces.
| Dimension | Generic Scanners | ThreatGraph |
|---|---|---|
| Focus | Detection | Remediation |
| Output | CVE lists | Version-specific upgrade recommendations |
| Automation | Alerting | Confidence-gated GitHub issue creation |
| Data strategy | NVD/AI-first | Package-native first, AI only for edge cases |
| Interfaces | Human dashboard | API + CLI + Agent Skill |
| Agent support | None | Agent-first architecture |
Real-looking artifacts from the remediation pipeline.
Join the waitlist for early access to ThreatGraph — remediation intelligence for your GitHub repositories.