{"uid":"cap_n6UTMlEAF8gNSLfbj_DaW","slug":"delx-commerce-dependency-version-risk-analyzer-c9dae669","name":"Delx Commerce — Dependency Version Risk Analyzer","description":"Pay-per-result APIs for agents. No signup. Exact price. Verifiable delivery. USDC on Base + Solana via x402.","url":"https://commerce.delx.ai/api/v1/x402/dependency-version-risk?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"dependencies":{"type":"object","description":"Input field: dependencies."}}},"responseSchema":{"type":"json","example":{"risk":"review","schema":"delx/util-dependency-version-risk/v1","advisory":"Version ranges do not replace vulnerability scanning or lockfile review.","unbounded":["example"],"unbounded_count":1,"dependency_count":2}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.003","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.003/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_UtXTjDVOiNbGk8wSE8Uft","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.003","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Analyzes a map of software dependencies and flags those with unbounded or risky version ranges that could introduce security or stability vulnerabilities.","exampleAgentPrompt":"Check my project dependencies for risky or unbounded version ranges — here they are: {\"express\": \"^4.0.0\", \"lodash\": \"*\", \"react\": \"18.2.0\"} — and tell me which ones are unsafe.","exampleUseCases":[{"title":"Pre-release dependency audit","prompt":"Before I ship this release, check these dependencies for unsafe version ranges: {\"axios\": \">=0.21.0\", \"webpack\": \"*\", \"typescript\": \"~5.0.0\"} — I want to know which ones are unbounded and what the overall risk level is."},{"title":"CI pipeline security gate","prompt":"As part of my CI check, scan these package dependencies for version range risks: {\"lodash\": \"^4\", \"express\": \"*\", \"moment\": \"2.29.4\"} — flag anything that could silently pull in a malicious or breaking version."},{"title":"Open-source project contribution review","prompt":"I'm reviewing a pull request that changes dependencies to {\"fastify\": \">=4.0.0\", \"pino\": \"*\", \"dotenv\": \"~16.0\"} — can you assess whether any of these version ranges are dangerously unbounded?"}],"resultDescription":"Returns a risk classification (e.g. 'review'), a list of unbounded dependency names, a count of unbounded packages, total dependency count, and an advisory note reminding that version range checks don't replace full vulnerability scanning or lockfile review. Uses schema identifier 'delx/util-dependency-version-risk/v1'.","failureModes":["Malformed dependencies object returns a validation error","Empty dependencies object may return zero counts with no risk signal","Non-standard version range formats may not be recognized as unbounded","Payment failure via x402 results in 402 response and no analysis"],"whenToPreferThis":"Choose this endpoint when you need a fast, pay-per-call check on whether dependency version specifications are dangerously permissive (e.g. using wildcards or open-ended ranges) without standing up your own tooling. It is particularly useful in automated agent pipelines, CI gates, or code review workflows where you want a structured risk signal with no signup or subscription overhead. It complements but does not replace full CVE/vulnerability scanning.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-01T00:53:38.293Z","isFirstParty":false,"canonicalSlug":"delx-commerce-dependency-version-risk-analyzer-c9dae669"}