NewStart your first free run
software inventory

A bill of materials you can ask questions of.

Every package that ends up inside your applications, what brought it there, and which of them a known vulnerability affects. Kept current by the same runs that test the application itself.

1,284 packages5 affected
rreact19.1.0
aaxios1.8.1high
zzod3.24.2
llodash4.17.20high
vvite6.2.2medium
eexpress4.19.2low
pprisma6.5.0
ttailwindcss4.1.3
next15.2.2criticalAuthorization bypass in middlewareDirect dependency · used by 2 assets
Fixed in15.2.3
01 / Working with it

From a package name to the line you change.

Each package opens into what affects it, what brought it in and what it takes to move it.

Matching

How a package becomes a finding.

Matched against the version in front of it, not against a name that looks similar. The resolved version is the one treated as proven; the range someone typed in a manifest is shown separately.

  • The worst severity against each package
  • The version that fixes it, and how many assets are affected
  • Open, fixed or ignored, per package
  • Or one row per advisory, searchable by CVE
Dependencies
directcritical[email protected]checked 4m ago
Advisories
Authorization bypass in middlewareOne request header makes Next.js skip middleware, so any sign-in check done there never runs.affected< 15.2.3· fixed in 15.2.3
Assets
app.acme.io interopt/web-dashboard
Resolved version, not the range^15.2.0 in package.json · 15.2.2 installed
Reachability

Why a package is there at all.

A transitive package is only in your build because something you declared depends on it. The shortest chain from each direct dependency is shown, so you know which name you can actually change.

  • A chain for every direct dependency that reaches it
  • Declared packages show where they are declared instead
Reachability
Declared by you
Pulled in by them
express
stripe
@acme/sdk
body-parser
superagent
qs6.11.0transitivemedium
Three routes in, and each one upgrades on its own.Bumping express does not change what stripe resolves.Fixed in6.11.1
Stack

The readable half, kept separate.

The full list runs to a thousand entries. The stack is the short version a person actually reads: the languages, frameworks, databases and infrastructure an asset is built on.

Assets
interopt/billing-api
OverviewFindingsScansTechnologiesDependencies
TechnologyVersionSource
Languages1
TypeScript5.6.3npm
Runtimes1
Node.js20.18.0—
Frameworks1
Express4.21.1npm
Data stores2
PostgreSQL16.4—
Redis7.4.1—
Infrastructure1
Docker——
6 technologies detected
Upgrading

An upgrade that moves what has to move with it.

Preview upgrade reads the repository and shows the manifest edits for the fixed version, along with any package coupled to it, across every place the package is listed.

  • Coupled packages are never upgraded on their own
  • Refreshed on the schedule you set, so it describes what runs today
Upgrading
cookie0.6.00.7.0 Open pull request
expresshas to move with it, to4.21.1
apps/api/package.json
14− "express": "^4.19.2",
14+ "express": "^4.21.1",
15− "cookie": "^0.6.0",
15+ "cookie": "^0.7.0",
apps/web/package.jsoncookie only
02 / Inventory

What the inventory records.

Built from what actually gets installed, not from what someone wrote down.

01

The exact version that ships

A rule like anything from 1.5 upwards is not an answer. Recorded here is the version that was installed.

02

The ones you chose, and the ones that came along

Most of what an application installs, nobody on your team picked. That is where the risk sits.

03

Every place a package is listed

In a large codebase the same package is listed in several projects, and changing one leaves the rest behind.

04

Why a package is there at all

The shortest chain back to something you did choose, which a plain list cannot answer.

03 / Questions

Questions about the inventory.

start here

See what is actually inside your applications.

Connect a repository and the first run returns the inventory alongside the findings, with the chains and the fix versions already worked out.