How OpenPulse works

From raw upstream signals to dependency-specific early warning — every step is evidence-first and inspectable.

01

Monitor the ecosystem

Seven source families are watched continuously: GitHub, OSV, NVD, MITRE CVE, CISA KEV, endoflife.date and container registries. Signals include lifecycle/EOL/EOS, vulnerabilities, licence changes, distribution and registry changes, ownership changes, repository health, breaking roadmap changes and release activity.

02

Analyse the change

Four analyst passes — Change, Security, Evidence and Report — classify what changed, assess security relevance, gather independent evidence, and draft a structured finding.

03

Pass the evidence gate

Nothing ships without evidence. Findings carry a confidence level — CONFIRMED, CORROBORATED, EMERGING or UNVERIFIED — and links to the sources behind them. No opaque risk scores.

04

Connect to your dependencies

Findings are matched — identity-aware, not name-aware — against the dependencies you actually use, so docker.io/bitnami/redis and docker.io/redis are never confused.

05

Report and watch

Results land in the Monthly Pulse and in watchlists, split into action-worthy, watch and informational items with recommended investigation steps.