Home / Companies / Endor Labs / Blog / Post Details
Content Deep Dive

Introducing JavaScript Reachability and Phantom Dependency Detection

Blog post from Endor Labs

Post Details
Company
Date Published
Author
Jenn Gile
Word Count
1,150
Company Posts That Month
7
Language
English
Hacker News Points
-
Post removed?
No
Summary

Endor Labs has introduced new software composition analysis (SCA) capabilities for JavaScript, TypeScript, and NodeJS, featuring reachability and phantom dependency detection, which help prioritize vulnerabilities across both direct and transitive dependencies. Reachability analysis determines if vulnerable code is being used in an application, and Endor Labs' approach does not rely on runtime agents, instead utilizing program analysis for comprehensive dependency coverage. This method contrasts with traditional manifest scanning, which can miss critical vulnerabilities due to discrepancies between declared and actual dependencies, such as phantom dependencies—packages used but not declared in the manifest. The tool supports package managers like yarn, npm, and pnpm, and automatically resolves dependencies in complex environments like workspaces. Endor Labs' program analysis provides a unified view of all dependencies by analyzing the application's source code and comparing it with a pre-populated vulnerability database, offering enhanced security insights beyond conventional SCA tools.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.