AppSecNews
SCA Commercial Growing

Endor Labs

by Endor Labs

A composition analysis platform that builds call graphs across application and dependency code to determine whether a vulnerable function is actually reachable before raising it.

Visit endorlabs.com (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run Endor Labs in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 2 points in this profile are not yet confirmed against vendor documentation.
  • Reachability analysis depth varies by language: confirm which languages have full call graph support
  • Current module list beyond dependency analysis: verify against vendor documentation

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

Endor Labs is built around one technique applied consistently: program analysis. Rather than stopping at "your lock file contains a package with a known vulnerability," it constructs a call graph spanning your first-party code and the dependency's code, then determines whether a path exists from your application to the specific function the advisory implicates. A vulnerability in a library you import but whose affected path you never touch is classified as unreachable and deprioritized, which is where most of a dependency backlog goes.

The same analysis supports the questions that come before remediation. Dependency selection scoring rates a candidate library on maintenance activity, security practice, popularity and known issues, so teams choose well rather than only patch later. Upgrade impact analysis uses the call graph to predict whether a version bump breaks your callers, which is the actual reason teams delay upgrades. Around that core the platform has grown SBOM and VEX generation, secret detection, CI/CD posture checks, container scanning and governance over open source and AI model adoption.

Where it fits

It runs in the pull request and the build pipeline through a command line scanner, with results in a SaaS console. Ownership is shared: security sets policy and watches the portfolio, developers see reachable findings on their pull requests. For reachability to mean anything the scan needs a resolvable build, and a language where call graph analysis is mature. Dynamic languages and heavy reflection reduce precision, a property of the technique rather than of this vendor.

Strengths

  • Function-level reachability cuts the number of findings a team must look at, which is the difference between a working program and a growing backlog.
  • Upgrade impact prediction addresses the real blocker to remediation, not just the detection of it.
  • Findings carry the call path as evidence, so a developer can verify the claim rather than take it on faith.

Limitations

  • Reachability precision is uneven across languages. Java and Go analysis is stronger than analysis of heavily dynamic code, and an unreachable verdict deserves more scrutiny in those languages.
  • Reflection, dependency injection and configuration-driven loading all break static call graphs, so unreachable does not mean unexecutable.
  • Scans that build a call graph take longer and need more compute than manifest parsing, which affects pipeline design.

Who it suits

The right choice for organizations drowning in dependency findings that have already tried severity-based prioritization and found it wanting, particularly JVM and Go heavy estates. Less compelling for small codebases where the backlog is manageable by hand, for teams whose primary need is license compliance, or where the dominant language sits at the weaker end of the call graph analysis.

Used Endor Labs? Recommend it under your own name and title.

Recommend this tool