- Home
- Application Security
- Software Composition Analysis
- Root Library Catalog (RLC)
Root Library Catalog (RLC)
Patches vulnerabilities in app dependencies at pinned versions without upgrades

Root Library Catalog (RLC)
Patches vulnerabilities in app dependencies at pinned versions without upgrades
Go Beyond the Directory. Track the Entire Market.
Monitor competitor funding, hiring signals, product launches, and market movements across the whole industry.
Root Library Catalog (RLC) Description
Root Library Catalog (RLC) is a managed patching service that addresses vulnerabilities in application dependencies across multiple package ecosystems including npm, PyPI, Maven, and Go. The service patches libraries at their pinned versions without requiring version upgrades or breaking changes. RLC operates through an AI-powered Agentic Vulnerability Remediation (AVR) platform that automates vulnerability detection, patching, testing, and delivery. The platform researches CVEs by collecting advisories, exploits, and upstream commits, then applies minimal security fixes through backporting rather than full version upgrades. Each patch undergoes package tests, functional tests, and CVE-specific validation by security researchers. The service delivers built-from-source patched artifacts with complete chain of trust documentation including provenance, attestation, SBOM in CycloneDX format, VEX, and before/after CVE delta reports. Libraries are delivered with modified version identifiers (e.g., django==4.2.1-root). RLC connects to artifact repositories or registries to automatically discover libraries in production use. The service operates on a contracted fix-rate throughput model with automatic prioritization of Critical and High severity vulnerabilities. CISA KEV vulnerabilities receive priority treatment regardless of capacity constraints. The service requires an active Root Image Catalog (RIC) subscription or equivalent base image support. It maintains native OS compatibility and integrates with existing security scanning tools to identify vulnerable libraries requiring remediation.
Root Library Catalog (RLC) FAQ
Common questions about Root Library Catalog (RLC) including features, pricing, alternatives, and user reviews.
Root Library Catalog (RLC) is Patches vulnerabilities in app dependencies at pinned versions without upgrades developed by Root.io. It is a Application Security solution designed to help security teams with Vulnerability Management, Dependency Management, Patch Management.
FEATURED
Fix-first AppSec powered by agentic remediation, covering SCA, SAST & secrets.
Cybercrime intelligence tools for searching compromised credentials from infostealers
Password manager with end-to-end encryption and identity protection features
Fractional CISO services for B2B companies to build security programs
POPULAR
Real-time OSINT monitoring for leaked credentials, data, and infrastructure
A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.
AI security assurance platform for red-teaming, guardrails & compliance
TRENDING CATEGORIES
Stay Updated with Mandos Brief
Get strategic cybersecurity insights in your inbox