{"uid":"cap_DG-1DXsiRfkYlLHN1Pxtf","slug":"synthora-deps-dev-resolved-dependency-graph-4941311d","name":"SYNTHORA deps.dev Resolved Dependency Graph","description":"Returns the fully resolved transitive dependency tree (direct + indirect nodes with pinned versions and relation type) for a package version, from keyless deps.dev. Powers autonomous agents doing supply-chain blast-radius analysis, dependency-confusion detection, and agent-to-agent SBOM generation. Ranking surface for dependency count and tree depth. First 3 calls FREE per wallet — send header X-WALLET: 0x<addr>. No charge on upstream failure.","url":"https://depsdev-dependency-graph.hergertsynthora.com/service","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"system":{"type":"string","description":"system"},"package":{"type":"string","description":"package"},"version":{"type":"string","description":"version"}}},"responseSchema":{"type":"json","example":{"ok":true,"niche":"depsdev-dependency-graph","result":{"system":"npm","package":"express","version":"4.18.2","depCount":0,"dependencies":[]},"provenance":{"url":"https://api.deps.dev/v3/systems/npm/packages/express/versions/4.18.2:dependencies","source":"deps.dev Resolved Dependency Graph"}}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.001","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.001/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_v1KgOc_z0vOiyvbFD07zj","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.001","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns the fully resolved transitive dependency tree (direct and indirect dependencies with pinned versions and relation types) for a given package version using deps.dev data.","exampleAgentPrompt":"Can you pull the full resolved dependency tree for express version 4.18.2 on npm — I want to see all the transitive packages it pulls in and the total dependency count?","exampleUseCases":[{"title":"Supply-chain blast-radius analysis","prompt":"Get me the complete transitive dependency graph for lodash version 4.17.21 on npm so I can assess how many downstream packages are exposed if a vulnerability is found in it."},{"title":"Automated SBOM generation for a release","prompt":"Fetch the full resolved dependency tree for django version 4.2.0 on PyPI — I need a complete list of all direct and indirect dependencies with their pinned versions to build an SBOM."},{"title":"Dependency confusion risk detection","prompt":"Resolve all transitive dependencies for log4j version 2.17.1 on Maven so I can check if any of the indirect packages have names that could be hijacked via dependency confusion."}],"resultDescription":"A JSON object containing the package system, name, version, total dependency count, and an array of all resolved dependencies (direct and transitive) with pinned versions and relation types, plus provenance metadata pointing to the originating deps.dev API URL.","failureModes":["Unknown or misspelled package name returns empty or error result","Unsupported package ecosystem (system) causes lookup failure","Package version not indexed by deps.dev returns empty dependency list","Network or upstream deps.dev API unavailability causes timeout or error","Malformed input (missing required fields) returns validation error"],"whenToPreferThis":"Choose this endpoint when you need the complete transitive (not just direct) dependency graph for a specific package version across major ecosystems (npm, PyPI, Maven, Go, etc.), especially for supply-chain analysis, SBOM generation, or dependency confusion detection. Prefer it over parsing lock files when you need a clean, structured, keyless API response without authentication overhead.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T12:37:06.770Z","isFirstParty":false}