AI coding agents like Claude Code, Codex, and Cursor generate code and pull requests faster than application security teams can review them. This shift in development speed breaks the foundational assumptions of traditional AppSec tools.
To address these changing dynamics, Gartner has named Endor Labs a Sample Vendor in two categories within the Gartner® Hype Cycle™ for Secure Software Engineering, 2026: Software Supply Chain Security and Reachability Analysis. This dual recognition shows that the market is moving toward the core architecture we chose when building our platform.
The scale problem in agentic development security
Before AI coding tools emerged, engineering teams already imported more third-party code than they could vet or audit manually. The adoption of AI coding agents has worsened this issue. AI coding agents routinely pull in unvetted dependencies, suggest non-existent packages, and produce a volume of pull requests that human backlogs cannot handle.
The traditional security playbook cannot scale to fix this. Running a SAST scan, exporting a flat Software Bill of Materials (SBOM), and handing developers thousands of unprioritized "critical" alerts fails in an automated environment. When AI accelerates both code generation and exploit development, sending alerts without operational context becomes a liability. Security teams must quickly isolate which risks actually matter.
Why you need reachability analysis and software supply chain security
The two categories we were named in aren't separate stories. They're the same story told at two altitudes.
Software supply chain security is the surface area. Every dependency, container layer, CI/CD pipeline, secret, and now every AI agent and MCP server touching your codebase is part of the attack surface you're responsible for, and none of it fits in a spreadsheet. Endor Labs maps that entire surface with a code context graph, giving platform and security teams one continuous view of what's running across their repos and services.
Reachability analysis is how you make that surface manageable. Traditional software composition analysis (SCA) flags a vulnerability the moment a vulnerable package appears in your manifest. Endor Labs goes deeper, analyzing the call graph across direct and transitive dependencies to determine whether your application actually invokes the vulnerable function. If the code path isn't reachable, it isn't exploitable in your environment. That distinction lets teams safely dismiss 92% of SCA noise instead of drowning in it.
Why this matters in the Mythos moment
We've hit what I'd call the Mythos moment, borrowing the name of Anthropic's newest model tier: the point where frontier AI finds vulnerabilities faster than the world can fix them. Since Anthropic's Project Glasswing kicked off, more than 23,000 vulnerabilities were identified across over 1,000 open-source projects in the first month alone, more than 6,000 of them high or critical. Fewer than 5% had been fixed as of mid-June. The curl project, whose code runs on tens of billions of devices, closed its vulnerability intake entirely for a month because maintainers couldn't keep up with the flood of AI-generated reports.
The same models defenders are pointing at open source this morning will be in attackers' hands soon after. The time-to-exploit window is collapsing. When your organization is suddenly handed 10,000 validated findings, “patch everything” isn't a plan.
Reachability answers the question that actually matters at that point: where do I start. It turns an undifferentiated wall of criticals into a ranked list of what threatens your applications first, so your team spends its hours on the handful of flaws that are reachable and exploitable. And once you know what to fix, we do the harder part: author a verified, tested fix. It's the same engine behind Endor Zero-Day Patches, which delivers fixes for novel open-source vulnerabilities in under 24 hours, before there's an upstream patch or even a CVE.
Put those together and you get what engineering teams have been asking for: evidence, and a path to a fix. A short list of what's reachable, exploitable, and worth your sprint, with the patch already written.
What this signals about the future
We've argued for a while that security has to be built into how software gets developed rather than bolted on at the end of the pipeline. Customers tell us the same thing every week: developers need guardrails that keep pace with AI, and security teams need the context to know which findings are real.
That's the platform we've been building. Being named twice is a good sign we're building it in the right place. To see how Endor Labs maps and secures the modern software supply chain, with reachability at the core, request a technical demo.
Disclaimer
Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner's research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose. GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally, and HYPE CYCLE is a registered trademark of Gartner, Inc. and/or its affiliates and are used herein with permission. All rights reserved.
Gartner, Hype Cycle for Secure Software Engineering, 2026, Aaron Harrison, 2 June 2026.
What's next?
When you're ready to take the next step in securing your software supply chain, here are 3 ways Endor Labs can help:








