Skip to main content

0607Monitoring

Stay compliant as dependencies change

Publish drift visibility, license-version advisory, repo auto-sync, and optional vendor-only security monitoring.

Last updated: July 2, 2026

Drift detection

A stale compliance page is a liability. This one tells on itself.

When your inventory moves past what buyers can see, SourceTrust says so: A dashboard banner, per-project status pills, and a Changes tab that lists exactly what moved. Publishing clears it, and auto-sync plus publish-on-merge can close the loop without you.

  • Your public page is out of date: The banner names the stale revision and what changed since
  • Status pills on every project: Published and fresh, or n changes since rev 12
  • The Changes tab lists new, updated, and removed packages since the published snapshot

Publish-on-merge closes the loop

Security monitoring, vendor-only

Know about the CVE before your buyer does. Privately.

An add-on checks every dependency against OSV.dev and the GitHub Advisory Database, daily and on every sync, import, and publish. Findings are deliberately vendor-only: They never appear on your public page, because a compliance page should not double as a vulnerability map.

  • Live packages, flagged first

    Advisories on packages in your published revision carry a Production live tag and a severity, so triage starts where exposure is real.

    Production (live): 2 advisories

  • Alert emails with signal, not noise

    Recipients hear only about new or upgraded critical and high findings on live packages, never every scan. One deep link lands on the Security tab.

  • Review-time warnings

    On private repos with the add-on, the review comment warns about known vulnerabilities in the exact versions the change introduces, before they merge.

  • Never on the public page

    Buyers see your license posture, not your open findings. Security stays between you and your team.

Stop shipping on assumptions

Map your obligations before the next release

Set up a project for each repo, review your obligations, publish when ready, and keep the record aligned with every release. Download license and attribution files when engineering needs them, with pipeline checks so the next update does not undo what you already approved. Your SOC report is not a substitute.

Not ready to start yet? View pricing

Cookies on sourcetrust.dev

We use essential cookies for security, including abuse prevention on our site scan and walkthrough request form. With your permission, we also use optional analytics and diagnostics (Google Tag Manager on this site, and the Sentry browser SDK on the SourceTrust application when configured). See our cookie policy.