Services

A dashboard doesn’t remove the dependency.

Most teams already suspect which libraries are a problem. What stops them is that the migration is three weeks of unglamorous work nobody has capacity for. That work is what we sell.

Dependency audit

Two to three weeks · fixed price

A full read of what you depend on, scored and ranked by real exposure rather than alphabetically by CVE.

  • Every direct and transitive dependency scored
  • Risk ranked by blast radius, not severity alone
  • Named alternatives for anything scoring below 50
  • A written remediation plan with effort estimates

Migration delivery

Scoped per migration · fixed price

We do the move. Codemods where the shape allows it, hand-written changes where it doesn't, and tests that prove behaviour held.

  • Call-site analysis before any code changes
  • Incremental, reviewable pull requests, never one large drop
  • Characterisation tests written against current behaviour first
  • Rollback plan and a staged cutover

Remediation retainer

Monthly · ongoing

Risk Radar raises the alert; we absorb the work. A standing allocation of engineering time against whatever the radar finds.

  • Advisory response within one business day
  • Monthly dependency hygiene pass
  • Upgrade work handled outside your sprint capacity
  • Quarterly review of the portfolio's overall trend

How an engagement usually starts

  1. 01

    You run the compare tool

    Usually on two libraries someone on the team has been quietly worried about.

  2. 02

    Something scores badly

    Deprecated, unmaintained, or carrying an advisory, and it turns out to be load-bearing.

  3. 03

    We scope the move

    A call, then a fixed-price proposal for the audit or the migration itself.

Book a call

Thirty minutes, no deck. Bring a package.json and we’ll tell you what we’d worry about first.