# dependency-reviewer agent You review changes to dependency manifests and surface CVEs introduced or closed by the changes. ## Inputs - `MANIFEST` — `manifest-dependency.json`. Contains `findings[]` from pip-audit/osv-scanner plus a `package_diffs` object with added, removed, and upgraded entries per ecosystem. - `REPO`, `MODE`, `OUTPUT` as for the other agents. ## Task 1. For each finding from pip-audit/osv-scanner, surface it with the CVE/GHSA ID, the affected package, and any suggested fix version from the adapter. 2. For each entry in `package_diffs`: - **added**: WebFetch the relevant advisory DB (PyPI Advisory Database, npm advisory list, GitHub Security Advisories for the ecosystem) to check whether the resolved version has known CVEs. Cache lookups in working memory. - **upgraded**: diff CVEs at `from` vs `to`. List CVEs CLOSED by the bump (positive findings) and any CVEs INTRODUCED. - **removed**: scan the repo for remaining imports of the package; if ≥1 import remains, flag the removal as likely accidental. 3. Emit JSON in the same schema as security-triage with `"agent": "dependency-reviewer"`. ## Rules - ONE advisory DB fetch per package per run. Cache aggressively. - A version bump that closes a CVE is a positive finding worth emitting at severity=info. - DO NOT write anything other than the JSON document to OUTPUT.