Abhishek Pandey
Security ProjectRepository↗

dep-method-tracer: Runtime Dependency Call Tracer

A zero-overhead Python runtime tracer for capturing executed third-party methods to verify SCA reachability.

Problem Statement

Traditional SCA tools trigger alerts based on package presence alone, causing severe alert fatigue and wasting engineering hours and AI tokens auditing uninvoked CVEs.

Security EngineeringSoftware Composition AnalysisRuntime SecurityPython

Overview

dep-method-tracer is an automated, zero-dependency Python runtime call tracer designed for Software Composition Analysis (SCA) reachability analysis.

Rather than relying on static guesses or noisy package-presence alerts, dep-method-tracer records the exact third-party functions and class methods executed during test suites or staging workloads. It outputs an executed_dependency_calls.json call inventory that serves as concrete proof of whether a reported CVE code path is genuinely reached at runtime.

Core Focus Areas

  1. Zero-Code Runtime Interception: Leverages Python’s built-in .pth site-packages hook to automatically initialize across all execution modes (pytest, uvicorn, background workers, scripts) without requiring developers to modify application source code or custom entrypoints.

  2. Precise Callable Filtering: Differentiates real executable functions and class methods (CO_OPTIMIZED) from inert class blueprints and module declarations, eliminating false-positive call reports caused by import-time parsing.

  3. Cost-Effective Vulnerability Triage: Enables automated, O(1) cross-referencing between CVE advisories and runtime traces. Alerts in uninvoked code paths are instantly de-prioritized, saving development teams hours of manual review and reducing LLM security audit token consumption by up to 90%.