0607Monitoring
Stay compliant as dependencies change
Publish drift visibility, license-version advisory, repo auto-sync, and optional vendor-only security monitoring.
Last updated: July 2, 2026
Drift detection
A stale compliance page is a liability. This one tells on itself.
When your inventory moves past what buyers can see, SourceTrust says so: A dashboard banner, per-project status pills, and a Changes tab that lists exactly what moved. Publishing clears it, and auto-sync plus publish-on-merge can close the loop without you.
- Your public page is out of date: The banner names the stale revision and what changed since
- Status pills on every project: Published and fresh, or n changes since rev 12
- The Changes tab lists new, updated, and removed packages since the published snapshot
Security monitoring, vendor-only
Know about the CVE before your buyer does. Privately.
An add-on checks every dependency against OSV.dev and the GitHub Advisory Database, daily and on every sync, import, and publish. Findings are deliberately vendor-only: They never appear on your public page, because a compliance page should not double as a vulnerability map.
Live packages, flagged first
Advisories on packages in your published revision carry a Production live tag and a severity, so triage starts where exposure is real.
Production (live): 2 advisories
Alert emails with signal, not noise
Recipients hear only about new or upgraded critical and high findings on live packages, never every scan. One deep link lands on the Security tab.
Review-time warnings
On private repos with the add-on, the review comment warns about known vulnerabilities in the exact versions the change introduces, before they merge.
Never on the public page
Buyers see your license posture, not your open findings. Security stays between you and your team.
Continue reading
Related topics
One idea per page: Follow the path that matches your next question.
Stop shipping on assumptions
Map your obligations before the next release
Set up a project for each repo, review your obligations, publish when ready, and keep the record aligned with every release. Download license and attribution files when engineering needs them, with pipeline checks so the next update does not undo what you already approved. Your SOC report is not a substitute.
Not ready to start yet? View pricing