Skip to main content

Monitoring

Know when your record needs attention.

See dependency drift and license changes. Add private security monitoring when you need it.

Drift detection

See drift before buyers do.

Compare the live page with the current inventory, review what changed, then publish a fresh revision.

  • A banner names the stale revision.
  • Each project shows whether its published record is fresh.
  • The Changes tab groups added, updated, and removed packages.
Automation

When enabled, publish on merge refreshes your page after the review gates pass.

Publish-on-merge closes the loop
Illustrative exampleAcme Platform
Your public page is out of date

Buyers still see revision 12 from June 30. 3 package changes, 1 license change.

PackagePublished · rev 12Inventory
charting-lib1.4.2MIT2.0.0Apache-2.0
date-fns3.6.0MIT4.0.0MIT
pino8.19.0MIT8.21.0MIT
sourcetrust.app/acme/platform

Published revision 12 · June 30

Optional add-ons

Private CVE alerts for live dependencies.

An add-on checks every dependency against OSV.dev and the GitHub Advisory Database, daily and on every sync, import, and publish. Findings are deliberately vendor-only: They never appear on your public page, because a compliance page should not double as a vulnerability map.

Security monitoring, vendor-only

Live packages, flagged first

Advisories on packages in your published revision carry a Production live tag and a severity, so triage starts where exposure is real.

Illustrative exampleProduction (live): 2 advisories

Alert emails with signal, not noise

Recipients hear only about new or upgraded critical and high findings on live packages, never every scan. One deep link lands on the Security tab.

Review-time warnings

On private repos with the add-on, the review comment warns about known vulnerabilities in the exact versions the change introduces, before they merge.

Start with the files you already have.

Free to import and review. No credit card needed.

Start for free

Cookies on sourcetrust.dev

We use essential cookies for security, including abuse prevention on our site scan and walkthrough request form. With your permission, we also use optional analytics and diagnostics (Google Tag Manager on this site, and the Sentry browser SDK on the SourceTrust application when configured). See our cookie policy.