# dependency-vulnerabilities

Published articles for dependency-vulnerabilities.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## From Theory to Practice: Three Small Tools for Big Security Problems

DevFeed: [From Theory to Practice: Three Small Tools for Big Security Problems](<https://devfeed.tech/articles/from-theory-to-practice-three-small-tools-for-big-security-problems-62602.md>)

Original publisher: [Read original article](<https://hackernoon.com/from-theory-to-practice-three-small-tools-for-big-security-problems?source=rss>)

Author: Renan Botasse

Published: 2026-09-30T15:38:43Z

Content type: article

Language: en

Sources: [HackerNoon](<https://devfeed.tech/sources/hackernoon.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>), [Secret Scanning](<https://devfeed.tech/topics/secret-scanning.md>)

Tags: [ai-generated-code](<https://devfeed.tech/tags/ai-generated-code.md>), [ci](<https://devfeed.tech/tags/ci.md>), [cicd-security](<https://devfeed.tech/tags/cicd-security.md>), [cves](<https://devfeed.tech/tags/cves.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [cyclonedx](<https://devfeed.tech/tags/cyclonedx.md>), [dependency-vulnerabilities](<https://devfeed.tech/tags/dependency-vulnerabilities.md>), [github](<https://devfeed.tech/tags/github.md>), [poetry](<https://devfeed.tech/tags/poetry.md>), [python](<https://devfeed.tech/tags/python.md>), [python-security](<https://devfeed.tech/tags/python-security.md>), [scanner](<https://devfeed.tech/tags/scanner.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [what-is-sbom](<https://devfeed.tech/tags/what-is-sbom.md>)

### AI overview

The author describes three small Python tools addressing software security: identifying vulnerable dependencies, determining whether vulnerabilities are reachable in code, and finding exposed secrets. The tools use vulnerability databases and can integrate checks into CI; the article also notes limitations and the need for human review of AI-generated code.

### Source excerpt

AI writes fast and leaves API keys in your code. I built three tiny Python tools to find vulnerable packages, reachable CVEs and leaked secrets.