Live packages, flagged first
Advisories on packages in your published revision carry a Production live tag and a severity, so triage starts where exposure is real.
Illustrative exampleProduction (live): 2 advisories
Monitoring
See dependency drift and license changes. Add private security monitoring when you need it.
Drift detection
Compare the live page with the current inventory, review what changed, then publish a fresh revision.
When enabled, publish on merge refreshes your page after the review gates pass.
Buyers still see revision 12 from June 30. 3 package changes, 1 license change.
| Package | Published · rev 12 | Inventory |
|---|---|---|
charting-lib | 1.4.2MIT | 2.0.0Apache-2.0 |
date-fns | 3.6.0MIT | 4.0.0MIT |
pino | 8.19.0MIT | 8.21.0MIT |
sourcetrust.app/acme/platformPublished revision 12 · June 30
Optional add-ons
An add-on checks every dependency against OSV.dev and the GitHub Advisory Database, daily and on every sync, import, and publish. Findings are deliberately vendor-only: They never appear on your public page, because a compliance page should not double as a vulnerability map.
Security monitoring, vendor-only
Advisories on packages in your published revision carry a Production live tag and a severity, so triage starts where exposure is real.
Illustrative exampleProduction (live): 2 advisories
Recipients hear only about new or upgraded critical and high findings on live packages, never every scan. One deep link lands on the Security tab.
On private repos with the add-on, the review comment warns about known vulnerabilities in the exact versions the change introduces, before they merge.
Free to import and review. No credit card needed.
Cookies on sourcetrust.dev
We use essential cookies for security, including abuse prevention on our site scan and walkthrough request form. With your permission, we also use optional analytics and diagnostics (Google Tag Manager on this site, and the Sentry browser SDK on the SourceTrust application when configured). See our cookie policy.