Observed arrival · 2026-10-05
Panopticode follows taint across repository boundaries
Panopticode describes a static-analysis engine that joins code graphs from multiple repositories to trace untrusted data from source to sink.
○Open
⊠Login
$Paid
†Ads
✦Pretty
●Pro
◎Niche
◉Human
⚑Risk
ƒJS
- For
- Teams scanning applications split across repositories
- Worth noticing
- The example joins a Svelte search page, GraphQL and gRPC calls, and a Go SQL handler into one taint route.
Field notes
The example breaks the route into named steps: a Svelte page reads ?q=, a TypeScript service calls GraphQL, and Go services carry the value through gRPC to a SQL operation. The site describes code graph files as the handoff between language-specific frontends and the analysis engine, with contract names used to connect remote calls to handlers. It also says the same engine can analyze a single-repository application.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
○OpenPublic substance visible
✦PrettyNotable craft visible
◎NicheUnusually specific use
One card from the complete issue