{
  "id": 11390253,
  "title": "Does Dependency Security Really Need the Cloud?",
  "url": "https://urgent.news/2026/10/02/does-dependency-security-really-need-the-cloud",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-02T07:53:00.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/gap_hunterlabs/does-dependency-security-really-need-the-cloud-3pki"
  },
  "original_language": "en",
  "account": "The question of whether dependency security truly requires cloud-based solutions arises from a desire to understand if a dependency vulnerability analyzer can function entirely locally. This consideration led to the development of Dependency Vulnerability Companion, an IntelliJ-family plugin that performs vulnerability checks without needing an internet connection, an account, token, API key, or any network calls during analysis.\n\nThe core of the analyzer's architecture involves parsing a project file, normalizing the dependency, matching it against a local vulnerability database, and performing an IntelliJ inspection. The plugin contains a versioned vulnerability database within its JAR, sourced from OSV bulk data. At runtime, the plugin reads this data locally, making the core vulnerability check independent of network availability.\n\nThe plugin currently supports dependency declarations in several formats, including pom.xml, build.gradle, build.gradle.kts, package.json, and requirements.txt. The initial parsers are kept relatively lightweight, focusing on extracting key information like the ecosystem, package, version, and source location. This representation allows the vulnerability matching layer to operate without needing to understand the original ecosystem-specific declaration syntax.\n\nOne critical aspect of the analyzer is its ability to retain source offsets, enabling it to pinpoint the exact location of a vulnerable dependency within the original source file. This feature enhances the usefulness of the analysis by providing concrete information, such as \"This declaration in the file you're editing matches a known vulnerable version.\"\n\nThe analyzer's approach to version comparison is particularly noteworthy. It must handle various version ranges and boundaries across different ecosystems, ensuring that it accurately determines whether a given version is affected by a known vulnerability. The current implementation avoids attempting to resolve complex dependency expressions or property resolutions, focusing instead on reliably analyzing declarations that can be processed with the available information.",
  "summary": "The question I kept asking myself a simple question: Why does checking a dependency for a known vulnerability need to send anything to the cloud? This isn't an argument against cloud-based security tooling . There are good reasons to use centralized services, especially when you need continuously updated data, organization-wide policies, reporting, or large-scale analysis. I was interested in a…",
  "key_points": [
    "Dependency Vulnerability Companion operates locally without internet",
    "Parses project file, matches against local vulnerability database",
    "Supports multiple dependency declaration formats for vulnerability checks"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}