Example workspace. A real scan of a polyglot monorepo with 20 real packages across npm, PyPI, Go, Cargo, NuGet and RubyGems, saved on 2026-09-30. It’s read-only, so nothing here changes a real project.Scan your own software
example-monorepo
grade C · last checked 5 days ago · 1 recent history entry
This is your baseline. You’ll see a comparison after the next scan.
Score over time
higher is better
64 → 64 over 1 scan
Scan history
newest first
When
Change
Grade
2026-09-30 21:20 UTC
SBOM uploaded
181 appeared
3
85
92
1
C
Longest standing
still present in the latest scan
Advisory
Component
First seen
CVE-2022-34265
django
at least 5 days ago
CVE-2023-24580
django
at least 5 days ago
CVE-2018-25032
nokogiri
at least 5 days ago
CVE-2023-46695
django
at least 5 days ago
CVE-2022-23833
django
at least 5 days ago
CVE-2023-23969
django
at least 5 days ago
CVE-2021-35042
django
at least 5 days ago
CVE-2024-25126
rack
at least 5 days ago
CVE-2024-21907
Newtonsoft.Json
at least 5 days ago
CVE-2022-29078
ejs
at least 5 days ago
“No longer present” means the finding is gone from the inventory. Usually it was fixed, but a component can also disappear when a source is removed or a dependency is dropped, so it doesn’t prove anyone fixed it. A first-seen date reads “at least” when the finding was already in the oldest scan we still keep.