Agentix package recommendations
When a package has high operational risk or multiple CVEs, you can use Cortex Agentix to generate data-driven recommendations for safer alternative packages directly from the side card.
Prerequisites
Cortex Agentix with the AppSec Agent available and enabled in the tenant
Agentix content enabled for the tenant's region. If Agentix is not available in the region or the AppSec Agent content is not enabled, the Show alternatives action does not open the Agentix sidecar
An identity with permission to run the Cortex Agentix AppSec Agent
Open the package side card for the package you want to replace: Navigate to Modules > Supply Chain Security > Package Explorer > select the package from the table.
In the Overview tab, locate the Highlights section and select Show alternatives. Expected outcome: The Cortex Agentix sidecar opens and the AppSec Agent runs a prompt scoped to the selected package and version.
What happens next: The AppSec Agent returns alternative-package recommendations in the Agentix sidecar. Use the recommendations to choose a safer default during design and development.
Agentix prompt types for Package Explorer
The Show alternatives action seeds the Agentix sidecar with a prompt scoped to the selected package@version. The AppSec Agent supports the following prompt types for Package Explorer packages.
Safer alternative
The package has multiple CVEs and elevated operational risk, and you want a drop-in replacement
An alternative OSS package that provides similar functionality and capability to the selected package@version, prioritizing lower vulnerability exposure and operational risk
Risk explanation
You need to justify a remediation decision or understand why the package is flagged
A plain-language explanation of the package operational risk and vulnerability exposure, grounded in the package popularity, maintenance, and CVE signals
Migration guidance
You have selected a replacement and need to plan the upgrade
Step-by-step guidance for migrating from the selected package@version to a recommended alternative, including breaking-change considerations
NOTE: The available prompt types depend on the AppSec Agent content enabled for the tenant. If a prompt type is not enabled, the Agentix sidecar does not offer that prompt.
Last updated
Was this helpful?
