Vai al contenuto
AI.info

tools

DeepSource

DeepSource reviews code changes for bugs, security issues, dependencies, secrets, coverage, and infrastructure misconfigurations.

DeepSource

In inglese

DeepSource connects to GitHub, GitLab, Bitbucket, or Azure DevOps and analyzes commits and pull requests. It combines static analysis with AI review, Autofix, secrets detection, dependency vulnerability scanning, code coverage, license checks, IaC review, and compliance reporting.

It is used by individual developers, open-source teams, and engineering organizations. Individual and Open Source plans are free, while software composition analysis is a paid add-on and AI features can incur metered charges.

Features

  • Reviews pull requests for bugs, security vulnerabilities, anti-patterns, and style issues
  • Provides AI-powered Autofix patches for detected issues
  • Scans secrets such as API keys, tokens, and credentials
  • Scans dependencies for CVEs with reachability analysis and auto-remediation
  • Tracks line, branch, and composite code coverage
  • Reviews Dockerfiles, Terraform plans, and Ansible playbooks
  • Provides GraphQL API, open-source CLI, and real-time webhooks

Use cases

  • Review pull requests for code quality and security issues
  • Find exploitable vulnerabilities in open-source dependencies
  • Block merges when coverage or security thresholds are not met
  • Detect leaked credentials before they reach production
  • Check infrastructure-as-code for security misconfigurations
  • Generate compliance reports for OWASP Top 10, CWE/SANS Top 25, and MISRA C

Pros

    Cons

      Latest updates

      • Reachability analysis for Java

        DeepSource SCA now runs reachability analysis on Java projects built with Maven.

      • Enterprise Server v5.0.2 (v5.0.2)

        DeepSource SCA now runs on monorepos. AI Review expanded to ten languages. Enterprise Server now supports the Kubernetes Gateway API.

      • Upgrades to AI Review Engine

        AI Review has new underlying models, improved analysis pipelines, two review tiers, mention-triggered runs, and processed LOC billing.

      • Configure New Vulnerability Alerts

        Configure email recipients, organization-admin notifications, and the minimum severity level for new vulnerability alerts.

      • DeepSource MCP Server

        The MCP Server exposes 30 tools across 8 categories for code review findings, PR grades, vulnerabilities, metrics, compliance reports, and issue suppression.

      Capabilities

      • Knows the whole codebase — “Scan your entire existing codebase and track code health and security hotspots over time.” source
      • Runs commands — “GraphQL API, open-source CLI, and real-time webhooks for integrating DeepSource into your workflows.” source
      • Reviews pull requests — “Catch bugs, anti-patterns, and security vulnerabilities on every pull request.” source
      • Command line — “GraphQL API, open-source CLI, and real-time webhooks for integrating DeepSource into your workflows.” source
      • Self-hosted — “Self-hosted deployment” source
      • API — “full GraphQL API and real-time webhook events.” source

      Get it

      Pricing

      Starting price
      $24/user/mo
      Prices checked
      2026-09-25

      Team

      • $24 per user/month
      • $30 per user/month
      • Unlimited repositories
      • Unlimited pull request reviews
      • Unlimited code formatting runs
      • AI Review and Autofix™
      • OSS Dependency Scanning
      • Support for monorepos

      Enterprise

      Price on request

      • Access to Enterprise Cloud
      • Self-hosted deployment
      • BYOK for AI Review
      • Single Sign-On (SSO)
      • Priority support with SLA
      • Dedicated account manager

      Open Source

      Free

      • Unlimited public repositories
      • Unlimited team members
      • 1,000 pull requests reviewed/month
      • AI Review: Pay-as-you-go
      • Autofix™: Pay-as-you-go
      • 1,000 automated code formatting runs/month
      Official website