# Delx Commerce — Dependency Version Risk Analyzer

> Delx Commerce — Dependency Version Risk Analyzer is a paid API for AI agents from commerce.delx.ai, paid per call via x402, $0.003/call, status unknown (last checked 2026-10-01).

Analyzes a map of software dependencies and flags those with unbounded or risky version ranges that could introduce security or stability vulnerabilities.

## Facts

- Endpoint: POST https://commerce.delx.ai/api/v1/x402/dependency-version-risk?utm_source=zero.xyz
- Price: $0.003/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-01
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/delx-commerce-dependency-version-risk-analyzer-c9dae669
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_n6UTMlEAF8gNSLfbj_DaW

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability delx-commerce-dependency-version-risk-analyzer-c9dae669 -d '<json body>'
```

Example prompt: Check my project dependencies for risky or unbounded version ranges — here they are: {"express": "^4.0.0", "lodash": "*", "react": "18.2.0"} — and tell me which ones are unsafe.

## When to prefer this

Choose this endpoint when you need a fast, pay-per-call check on whether dependency version specifications are dangerously permissive (e.g. using wildcards or open-ended ranges) without standing up your own tooling. It is particularly useful in automated agent pipelines, CI gates, or code review workflows where you want a structured risk signal with no signup or subscription overhead. It complements but does not replace full CVE/vulnerability scanning.

## Known failure modes

- Malformed dependencies object returns a validation error
- Empty dependencies object may return zero counts with no risk signal
- Non-standard version range formats may not be recognized as unbounded
- Payment failure via x402 results in 402 response and no analysis

## How this service works

Pay-per-result APIs for agents. No signup. Exact price. Verifiable delivery. USDC on Base + Solana via x402.

## Output

Returns a risk classification (e.g. 'review'), a list of unbounded dependency names, a count of unbounded packages, total dependency count, and an advisory note reminding that version range checks don't replace full vulnerability scanning or lockfile review. Uses schema identifier 'delx/util-dependency-version-risk/v1'.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "dependencies": {
   "type": "object",
   "description": "Input field: dependencies."
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "risk": "review",
  "schema": "delx/util-dependency-version-risk/v1",
  "advisory": "Version ranges do not replace vulnerability scanning or lockfile review.",
  "unbounded": [
   "example"
  ],
  "unbounded_count": 1,
  "dependency_count": 2
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/delx-commerce-dependency-version-risk-analyzer-c9dae669/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from commerce.delx.ai](https://www.zero.xyz/host/commerce.delx.ai/llms.txt)
