What happened
On Sept 30, 2026 Legit Security announced that its Agentic Remediation agent now covers vulnerabilities in open-source dependencies (direct and transitive), not just first-party code. The agent identifies the vulnerable package, finds the safest upgrade, applies the fix and regenerates lockfiles, re-scans pre/post to verify the resolution, opens a ready-to-review PR, and for major-version jumps adds an AI-assisted source-code adaptation layer (flagged as AI-assessed rather than independently verified).
Why it matters
As AI-generated code expands code volume, dependency-born vulnerabilities are the other major backlog driver AppSec teams cannot manually triage; verified, PR-ready automatic remediation directly attacks the find-to-fix gap for a leading source of CVEs. The explicit AI-verified vs AI-assessed distinction is a useful marker for the agentic-AppSec quality debate.
Applicability
AppSec/dev teams using Legit Security should test dependency remediation on high-risk transitive packages in staging before letting agents open PRs to production repos; review the flagged AI-adapted major-version changes manually.