How OpenPulse works
From raw upstream signals to dependency-specific early warning — every step is evidence-first and inspectable.
Monitor the ecosystem
Seven source families are watched continuously: GitHub, OSV, NVD, MITRE CVE, CISA KEV, endoflife.date and container registries. Signals include lifecycle/EOL/EOS, vulnerabilities, licence changes, distribution and registry changes, ownership changes, repository health, breaking roadmap changes and release activity.
Analyse the change
Four analyst passes — Change, Security, Evidence and Report — classify what changed, assess security relevance, gather independent evidence, and draft a structured finding.
Pass the evidence gate
Nothing ships without evidence. Findings carry a confidence level — CONFIRMED, CORROBORATED, EMERGING or UNVERIFIED — and links to the sources behind them. No opaque risk scores.
Connect to your dependencies
Findings are matched — identity-aware, not name-aware — against the dependencies you actually use, so docker.io/bitnami/redis and docker.io/redis are never confused.
Report and watch
Results land in the Monthly Pulse and in watchlists, split into action-worthy, watch and informational items with recommended investigation steps.
OpenPulse