Why I built it
A dependency alert leaves a maintainer with several jobs: read the advisory, find a suitable release, update the lockfile and run tests. Dependency Sentinel carries one upgrade through that review and leaves the final decision with the maintainer.
What it does
The agent inspects Python dependencies and selects a candidate supported by advisory and package-release evidence. The application stages the change in a disposable Git worktree, resolves the package environment, runs allowlisted validation commands and records the result. A maintainer reviews the diff and evidence, then approves a patch and receipt for download. The source checkout remains unchanged.
How it works
The React workbench and FastAPI gateway run on AWS EC2. The host's IAM role invokes Amazon Bedrock AgentCore. A Strands agent inside the runtime uses inspect_dependencies, lookup_advisories and lookup_release, then returns a typed CandidateSelection using Groq GPT-OSS 20B. AWS Secrets Manager holds its provider credential.
Deterministic code validates the candidate against OSV and PyPI evidence, stages the worktree and runs the permitted commands with timeouts. Model output cannot issue arbitrary shell commands or approve a patch. The review receipt captures the source revision, validation result, approval and patch hash. SQLite keeps each browser session's run history separate.
What I verified
The hosted recording uses the included owned repository, retrieves live OSV and PyPI evidence, proposes Jinja2 3.1.4 to 3.1.6, resolves dependencies and passes two package tests. The run pauses for approval before patch export. The original source revision and checkout remain unchanged. Regression tests cover failed validation, exact approvals, stale or altered records, exported bytes and session isolation.
Scope and tradeoffs
The public host executes only the included owned repository. It is not a service for executing arbitrary GitHub repositories. The local build supports other trusted repositories under an explicit allowed root; package installation and tests execute code and require a trusted environment. A passing test run does not prove an upgrade fixes every issue.
Judges can use the hosted workflow without an account or API key. AI requests are bounded, and saved records are tied to the browser cookie. The repository also includes a clearly labeled scripted local demo. No changes are pushed to GitHub and no pull request is created automatically.
I built this as a solo entrant with Codex for implementation, tests and documentation. The video uses synthetic Deepgram narration. Source, assets, locked dependencies, tests, setup instructions and the hosted architecture are public under Apache-2.0. The live model path is AgentCore, Strands and Groq rather than Bedrock foundation-model inference.
September 13 update
The workbench now groups the source revision, changed files and validation scope, and requires complete successful command evidence before enabling approval. On September 13, a fresh hosted run completed scan, validation, approval, patch export and receipt export. A bounded Groq reasoning-token fix is deployed in the existing AgentCore runtime.
New AWS Builder article: deadline checks, privacy previews, and reviewable patches.
Built With
- amazon-bedrock-agentcore
- amazon-ec2
- aws-secrets-manager
- fastapi
- groq
- osv
- pypi
- python
- react
- sqlite
- strands-agents-sdk
- typescript
Log in or sign up for Devpost to join the conversation.