Vercel has open-sourced a security scanning tool called deepsec.


This tool uses an agent investigation flow: first performing static scans to identify sensitive files, then having Claude and Codex trace data flows and review false positives, and finally exporting issues based on severity levels and responsible persons.
The official says that scanning a large repository on a single machine might take several days, but after deploying to Vercel Sandboxes, the process can be parallelized to over 1,000 instances.
I think application and service developers can try it out first; subscribing directly to the ready-made Claude or Codex is very practical.
It currently has about 1.2k stars on GitHub, and pure library projects can be added later, preferably with their own matchers and prompts.
Repository:
Note:
View Original
post-image
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin