Learn · ChangelogBrowse
LearnChangelog
What’s changed
Newest first, written from the project’s own history. We only list changes you can see or rely on, and leave out internal clean-up and tooling.
The report becomes a document you can file
- The printable report now opens with a cover and a one-page summary for someone who wasn’t in the room, then numbered sections, appendices and "Page X of Y" on every page. Its fingerprint is the SHA-256 of the JSON export, so a recipient can check the two match.
- The report page is now a single run sheet: the file, the answer, at most one notice naming the specific gaps, then tabs with the fix plan open. It’s about a third of its old length, and nothing was removed.
- Every report opens on a field with one square per finding, so you can see at a glance how many need attention first. The fix plan shows your progress as you mark upgrades done.
- Fix plan rows are now one line each, in reports and in projects. The detail is under Details.
- Report studio now shows the real report, so the preview, the printed PDF and the download are the same document.
- A downloaded report now looks the same in older viewers, such as mail and file previews on a phone.
- If a repository rescan fails because the GitHub App lost access to it, the project now says so and links to the installation settings where you can fix it.
- You get early access at sign-up after answering four short questions. It includes ten projects, daily monitoring, 90 days of history, branded reports and every export. You still don’t need an account to scan.
- Two new guides: preparing for the EU Cyber Resilience Act, and reviewing a supplier SBOM you can’t patch.
- We’ve published a privacy notice and terms, and you can now delete your account yourself. That also removes the sign-in identity behind it.
- Fixed: a security check added the same day blocked email sign-in and sign-out.
- Fixed two security problems found in an audit. A spreadsheet formula could be injected into an operator export through a profile field, and a sign-in form could be submitted from another site.
- You can save notification preferences for your account. Sending notifications by email or Slack isn’t live yet.
- Projects now list the licences declared in CycloneDX and SPDX files. History now tells new, gone, escalated and newly known-exploited findings apart.
- A fix plan row can now open a prefilled GitHub issue for you to review and submit yourself.
- A small Node.js script runs a scan from CI and fails the build on the tier you choose.
Checked upgrades and an example workspace
- Each recommended upgrade is checked against current advisories. If the target version is itself vulnerable, the plan moves to the next fixed version or says no safe target was found.
- Long OSV.dev result lists are now followed to the end. When that isn’t possible, the report says its results are incomplete instead of looking clean.
- A report with missing data no longer shows an overall grade as if nothing were missing, and it names stale exploit prediction scores.
- An example workspace, built from a real scan, that you can click through without an account.
- Branded reports with your company name and logo, and Report studio to preview them.
- Findings now open onto their evidence, and long tables of findings and components are split into pages.
- We reworked the workspace sidebar and scan page for smaller and shorter screens.
Accounts, projects and GitHub repositories
- Sign in and keep a project: its sources, its current report, and a timeline of what changed at each scan.
- Connect a GitHub repository. It’s read and scanned straight away, then again on the schedule you choose. Vendored code, tests and example directories are left out of the inventory.
- A nightly re-score applies the day’s CISA KEV and FIRST EPSS data to tracked projects, so a finding that becomes known exploited can move up without waiting for the next full scan.
- Each project has an overview, a plan, findings, components, history and settings. You can mute a finding with a reason, and tick an upgrade off when it’s done.
- Sign in with GitHub, Google, or an email address and password, and choose a different account at the provider when you need to.
- To keep an anonymous report, sign in from it. The original still expires as promised.
- Fixed: uploads over 10 MB were cut short and reported as invalid files.
- Fixed: signed-in pages could fail when a session was renewed.
First release
- Upload a CycloneDX or SPDX JSON SBOM, or your lockfiles and manifests, and get a short ranked fix plan instead of a list of CVEs.
- Components are matched against OSV.dev, marked when they are in the CISA KEV catalogue, and scored with FIRST EPSS. Each finding says why it landed in its tier.
- VEX statements in the SBOM are applied. The findings they cover are shown as suppressed instead of silently dropped.
- Upgrades target the lowest version that clears the most findings, rather than the latest release.
- Reports export as JSON, CSV and a self-contained HTML file, and are deleted after 24 hours.
- Check whether an SBOM is affected by one specific vulnerability.
- The layout works on phones down to 320px wide.
- Fixed: a client over its own rate limit could use up capacity meant for everyone else.
- An identical upload reuses a previous analysis for one hour at most, so a reused result is never built on day-old advisory data.
For the current state of the service, see the status page.