Risk over volume · not another PR bot

Parse supported manifests. Review what matters first.

Perpensa inventories nine shipped parser families, matches advisories, and ranks the resulting findings and update candidates—so AppSec and platform share one review queue.

No credit card. Deterministic scoring always on—AI is explainable and optional.

GitHub, GitLab, Bitbucket, Forgejo/Giteanpm, PyPI, Go, Maven, Docker, Cargo, Composer, NuGet, RubyGemsOSV + EPSS/KEV + SBOM
app.perpensa.dev
Update queue ranked by risk score with filters and review actions

Parser families shipped in this version

  • npm
  • PyPI
  • Dockerfile FROM
  • Go modules
  • Maven / Gradle
  • Cargo / crates.io
  • Composer
  • NuGet
  • RubyGems

Product

See the queue your team will live in

Current captures of the posture overview, risk-ranked queue, and matched findings. Sign in to open those screens in your workspace.

Try for free

Overview

Posture overview

Posture score, severity mix, and the top of the queue.

app.perpensa.dev
Perpensa posture overview with a score gauge, severity mix, and top of queue

Queue

Update queue

Risk-ranked remediations with KEV and exploit signals.

app.perpensa.dev
Update queue ranked by risk score with filters and review actions
Perpensa update queue on a mobile viewport

Mobile-ready triage

Queue and detail stay readable at ~390px. Primary actions stay thumb-friendly so on-call can act without a laptop.

Try for free

Findings

Findings

Triage open advisories with KEV, exploit, and EPSS signals.

app.perpensa.dev
Findings list with KEV and public exploit badges

Risk over volume

Not another upgrade bot

Renovate and Dependabot keep dependencies fresh. Perpensa tells you which findings and update candidates deserve review, why, and what to do first—with a shared queue and evidence for AppSec.

Risk over volume

A KEV-listed or high-exploit-probability finding before forty hygiene patches. Deterministic score first—always auditable.

Brain, not another arm

Renovate is excellent at automation. Perpensa is the triage layer AppSec and platform share.

Evidence, not just bumps

Findings, digests, CycloneDX/SPDX exports, and an audit trail — prove you are watching, not only merging.

Upgrade bots
Perpensa
  • Opens / groups PRs to keep packages fresh

    Ranks the queue by risk (CVE/severity, EPSS, KEV/public exploit, direct/transitive)

  • Noise is volume of bumps (tunable, still PR-centric)

    Prioritised queue + digests; optional remote PR

  • Lives in each repo’s config

    One org cockpit: findings, inventory, SBOM, policies

  • Needs write to open branches

    Read-first scan; public watch without push rights

Works alongside Renovate. Keep the bot for cadence and automerge; use Perpensa as the risk brain — triage, digests, SBOM, and optional remote PRs on writable npm repos. Other ecosystems stay queued for review, and Perpensa does not claim to replace Renovate's ecosystem depth.

Features

Built for teams who can't afford surprise outages

Stop sorting by severity alone. Perpensa turns supported dependency evidence into a prioritized review queue—scored by risk, shaped by policy, optionally re-ranked by AI.

  • Supported manifest inventory

    Parse npm, PyPI, Go, Maven/Gradle, Cargo, Composer, NuGet, and Bundler lock data, plus Dockerfile base-image references. Other package formats are not scanned yet.

  • Auditable risk scores

    Rank matched advisories with deterministic severity, EPSS, KEV/public-exploit, and direct/transitive inputs. Every factor remains visible.

  • AI prioritization

    Pro plans can re-rank from allowlisted inventory and advisory metadata. On failure, a deterministic heuristic delta is applied instead.

  • Policy engine

    Configure transitive-medium suppression, KEV guardrails, alert floors, and an open-PR limit. Policy actions are recorded for review.

  • Nine parser families, one queue

    npm and compatible JS lockfiles, PyPI lock and requirement files, Go modules, Maven/Gradle, Cargo.lock, composer.lock / composer.json, NuGet lock/csproj, Gemfile.lock, and Dockerfile FROM images.

  • Remote PRs on writable repos

    With VCS write access, open a remote PR that applies the recommended npm bump. Other ecosystems stay in the review queue.

  • Digest previews and delivery

    Build ranked email and Slack previews. Delivery requires a configured provider or per-org webhook; scheduled multi-tenant Slack remains store-only.

  • SBOM & audit-ready

    Export CycloneDX or SPDX SBOMs, findings and updates CSV, and a compliance bundle. Scan, AI, policy, and digest actions produce audit events.

How it works

From connect to digest in one continuous loop

Connect repositories, scan supported manifests, then review the queue, apply policy, and preview delivery on your own workspace.

  1. 01

    Connect your repos

    Connect GitHub, GitLab, Bitbucket, Forgejo, or Gitea credentials. Public GitHub watches stay read-only.

  2. 02

    Parse supported files

    Supported lockfiles, manifests, and Dockerfile FROM lines feed OSV matching.

  3. 03

    Score + policy

    Transparent risk score (0–100), then deterministic policies such as suppression floors and a KEV suppression guardrail.

  4. 04

    AI prioritize

    Optional AI re-ranks allowlisted update and finding metadata. Suggested actions remain explicit and auditable.

  5. 05

    Review & notify

    Leave advice unapplied or ignore it, create a remote PR when configured, and preview or deliver digests through configured channels.

AI copilot

Risk you can audit. Priority your team can act on.

Perpensa adds an LLM layer above the transparent risk score—not instead of it. Validated output structure, allowlisted inventory context, and human-or-policy final say.

How priority is built

Risk → AI priority
  1. 1

    Deterministic risk (0–100)

    Severity, EPSS, KEV/public exploit, and direct/transitive dependency status.

  2. 2

    Context pack

    Package, versions, advisory facts, and related findings—metadata only, not your source tree.

  3. 3

    LLM delta + rationale

    Validated JSON: priority adjustment, suggested action, citations. Low-confidence output stays advice for human review; on model failure, a deterministic heuristic delta is used.

  4. 4

    You decide — one click

    Applying a suggestion can request a remote PR or suppress with a reason. Both paths are audited.

Model output is validated JSON with structured citations. Vulnerability matching remains independent and uses OSV/semver; requested actions are re-checked against their own authorization and policy gates.

Pricing

Straightforward plans for the review queue

Monthly price per organization. Start free, then pick the pack that matches your seats and repos.

  • Starter

    For someone trying the queue on a few repos.

    Free
    • 1 seat
    • 3 repositories
    • 1 org-wide scan / 24h + weekly auto scan
    • Email risk digests
    • CycloneDX, SPDX, and CSV exports
    Start free
  • Recommended

    Pro

    For a serious operator or a small company.

    $49/ month
    • 5 seats
    • 25 repositories
    • Manual and webhook scan jobs
    • Custom scan and digest schedules
    • Remote PRs on writable npm repos
    • Optional AI prioritization
    • Email risk digests
    • Slack digests
    • CycloneDX, SPDX, and CSV exports
    Start Pro
  • Team

    For a larger account that needs several people on one tenant.

    $149/ month
    • 15 seats
    • 100 repositories
    • Manual and webhook scan jobs
    • Custom scan and digest schedules
    • Remote PRs on writable npm repos
    • Optional AI prioritization
    • Email risk digests
    • Slack digests
    • CycloneDX, SPDX, and CSV exports
    • Shared organization for multiple accounts
    Start Team

Shipped workflow

What the current product helps teams review

  • Shared triage

    Deterministic score + optional AI delta

    Review matched advisories in one risk-ranked queue instead of treating every version bump as equally urgent.

  • Conditional delivery

    Stored previews remain visible in-product

    Generate email or Slack previews, then deliver only when the corresponding provider or per-org webhook is configured.

  • Explicit handoff

    npm PRs apply the recommended bump

    Open a remote PR on a writable npm repo when credentials exist. Other ecosystems stay queued for the team to change and verify.

Explore the evidence before choosing an action

Sign in with GitHub to open a workspace—risk-ranked queue, findings, exports, policies, and optional AI prioritization.

Try for free

Auditable scores. Optional AI uses allowlisted inventory and advisory metadata—not the open web.