Overview
dep-method-tracer is an automated, zero-dependency Python runtime call tracer designed for Software Composition Analysis (SCA) reachability analysis.
Rather than relying on static guesses or noisy package-presence alerts, dep-method-tracer records the exact third-party functions and class methods executed during test suites or staging workloads. It outputs an executed_dependency_calls.json call inventory that serves as concrete proof of whether a reported CVE code path is genuinely reached at runtime.
Core Focus Areas
-
Zero-Code Runtime Interception: Leverages Python’s built-in
.pthsite-packages hook to automatically initialize across all execution modes (pytest,uvicorn, background workers, scripts) without requiring developers to modify application source code or custom entrypoints. -
Precise Callable Filtering: Differentiates real executable functions and class methods (
CO_OPTIMIZED) from inert class blueprints and module declarations, eliminating false-positive call reports caused by import-time parsing. -
Cost-Effective Vulnerability Triage: Enables automated, O(1) cross-referencing between CVE advisories and runtime traces. Alerts in uninvoked code paths are instantly de-prioritized, saving development teams hours of manual review and reducing LLM security audit token consumption by up to 90%.