If you run DeepSource in monorepo mode, today's release is for you. Monorepo mode lets you map subfolders of a single git repo as first-class repos on DeepSource, each with its own settings, dashboards, and configs. Until today, the one piece missing was SCA. That's fixed. Every sub-repo now gets its own Dependencies tab, with vulnerabilities scoped to the packages that sub-project actually uses. No noise from elsewhere in the monorepo. Clean ownership, clean triage. Two more updates in this release: AI Review just opened up to 10 more languages: Dart, Elixir, Apex, Groovy, Objective-C, VB.NET, PowerShell, Lua, Erlang, and Perl. Your PRs in these languages now get the full DeepSource review treatment. And for self-hosted teams: Enterprise Server now supports the Kubernetes Gateway API. If you've moved off Ingress, DeepSource fits in natively. Full notes: https://lnkd.in/gkE5pN_c
DeepSource
Software Development
San Francisco, California 5,462 followers
The AI code review platform for fast-moving teams and their agents.
About us
DeepSource is the AI Code Review Platform — built for engineering teams shipping code at the speed of AI. We combine battle-tested static analysis infrastructure with a deep AI review agent in a single hybrid engine. 5,000+ static analyzers build program intelligence — data-flow graphs, taint maps, reachability analysis — that grounds an AI agent capable of finding vulnerabilities other tools miss. 82% accuracy on real-world CVEs, the highest on the OpenSSF benchmark. More than code review: DeepSource is a complete platform for code quality and security. Static + AI analysis, secrets detection, code coverage tracking, software composition analysis, license compliance, baseline issue tracking, OWASP/SANS reporting, and flexible PR gates. One platform replacing a stack of point solutions. Native MCP support means DeepSource works with any AI coding agent your team uses — Cursor, Claude Code, Windsurf, Copilot — giving agents the feedback loop they need to write better code autonomously. Trusted by 6,000+ companies including Visa, Ancestry, Twilio, and WEX. SOC 2 Type II certified. Deploy on our cloud or self-host on your infrastructure. The way code gets written has changed. The way it gets reviewed should too.
- Website
-
https://deepsource.com
External link for DeepSource
- Industry
- Software Development
- Company size
- 11-50 employees
- Headquarters
- San Francisco, California
- Type
- Privately Held
- Founded
- 2018
- Specialties
- Developer Tools, Continuous Quality, Static analysis, Code quality, Code reviews, SCA, AI, DevSecOps, AI Code Review, and AI Code Security
Employees at DeepSource
Locations
-
Primary
Get directions
535 Mission St
San Francisco, California 94105, US
-
Get directions
100 Ft Road, Indiranagar
2004
Bengaluru, Karnataka 560008, IN
Updates
-
DeepSource AI Review now scores higher on the OpenSSF CVE Benchmark. Most importantly, we're seeing 4%+ gain on the F1 score. This means we're catching more real vulnerabilities without introducing a single false positive. Our precision hit 100% (zero false positives across 83 patched diffs) while recall climbed to 73.17%. Read our full results and methodology: https://lnkd.in/gXG-KZha
-
-
Introducing, DeepSource's MCP Server. This bring all of DeepSource natively in your AI agent. For instance, you can automate fixing code review issues in your PRs with DeepSource + Claude Code. Or, run a loop to automatically audit all vulnerabilities in OSS dependencies in your project. DeepSource provides reachability information, so any agent like Claude Code can effectively identify and upgrade packages to keep your project secure. We've shipped 30 tools in this release that help you do much more: identifying security vulnerabilities in existing code base, gathering code coverage data from across all projects in your organizations, creating custom reports, triaging and marking issues as false positives. Link to the full blog post in comments!
-
New: AI Review is now available on DeepSource Enterprise Server, with support for BYOK. This brings state-of-the-art AI code review and code security to self-hosted environments without your code passing through DeepSource Cloud or any third-party endpoint. Read more: https://lnkd.in/gusYSBP7
-
-
Studies suggest that most orgs take ~6mo on average to fix CVEs, but attackers exploit new CVEs in <5 days. DeepSource's new continuous CVE monitoring helps security teams change that. Our SCA engine now monitors vulnerability databases every hour. When a new CVE matches a dependency in your codebase, affected repos are re-scanned automatically and your team gets an email alert, so you can take action faster. Available now to all customers on DeepSource Cloud.
-
-
Introducing, BYOK for AI Review on DeepSource. The number one blocker we hear from enterprise teams evaluating AI code review: "We can't send our source code to a model provider we don't already have an agreement with." You can now bring your own model provider to DeepSource. Starting with support for Anthropic, OpenAI, and Google Gemini. DeepSource Enterprise Server gives you full control on how your source code is handled during code reviews. No code or data is shared with DeepSource. With this release, we bring the same guarantees for AI Review and all AI-powered features on DeepSource. If you have a BAA, a data residency agreement, or committed cloud spend, those terms cover AI Review automatically. No new vendor to approve, no new line item in procurement. BYOK is available to all teams on DeepSource Enterprise Server, starting today.
-
-
Meet the new DeepSource's CLI, built to make it easier for your AI coding agent to work with our code review results. Once the CLI is installed, get the DeepSource skill and just ask your agent to monitor DeepSource's review on a PR and fix. The CLI provides several flags to get details of the review — by category, severity, or per file. Install the skill: https://lnkd.in/gjf5NbEq Read the full changelog: https://lnkd.in/gNABUVa6
-