Scan your stack. Ship the fixes that actually matter.
Stackpulse inventories your dependencies, ranks updates with an auditable risk score, applies policy, then reorders work with an AI copilot—so security and platform ship the same queue.
No credit card. Deterministic scoring always on—AI is explainable and optional.
Prioritized updates
Base risk + AI delta
- expressCritical+4npm
AI: edge-facing API · KEV · open PR this week
CVE-2024-43796
4.18.24.21.2risk 96100Open PR - djangoCritical+2pypi
AI: ml-pipeline prod · public exploit signal
CVE-2024-45230
4.2.114.2.16risk 9193Open PR - lodashHigh-12npm
AI: transitive · unreachable template path → lower priority
CVE-2021-23337
4.17.204.17.21risk 7866Wait - reactLownpm
Hygiene patch — no CVE · schedule with next release
18.2.018.3.1risk 2222Batch - hashicorp/awsInfo-8terraform
AI: breaking provider schema · freeze window active
5.40.05.72.1risk 1810Defer
Trusted by engineering teams shipping at scale
- Northwind Labs
- Helix Cloud
- ParcelOps
- Orbit Finance
- Cascade Health
- Vantage AI
Interactive demo
The full loop is live—not a mockup
Connect a catalog GitHub install, run a fixture scan, apply policies and AI, open group PRs, then ship digests. Switch between Acme (Team) and Northstar (Starter) in the app sidebar — isolation is real. Adapters flip via env flags.
- 01
Scan
npm lockfile + multi-source advisories
- 02
Policy
Auto-suppress noise · KEV requires PR
- 03
AI rank
F21 on top of F05 risk score
- 04
Apply
One-click PR / suppress / group
- 05
Digest
Email + Slack Block Kit preview
- 06
Orgs
Switch demo tenants in-app
See the queue your team will live in
Real captures from the interactive demo—overview, risk-ranked updates, findings, and connected repos. Click any shot to open that screen.

Posture overview
Criticals, highs, and a 7-day trend at a glance.
- app.stackpulse.dev

Update queue
Risk-ranked updates across every ecosystem and repo.
- app.stackpulse.dev

Update detail
Why this rank—score breakdown, CVEs, and upgrade command.
- app.stackpulse.dev

Findings
Triage open advisories with KEV and exploit signals.
- app.stackpulse.dev

Repositories
Connected VCS repos, scan targets, and open risk.

Mobile-ready triage
Queue and detail stay readable at ~390px. Primary actions stay thumb-friendly so on-call can act without a laptop.
Try the queueFeatures
Built for teams who can't afford surprise outages
Stop chasing changelogs. Stackpulse turns dependency noise into a prioritized action plan—scored by risk, shaped by policy, sharpened by AI.
Full-stack inventory
One scan covers application deps, container base images, IaC providers, and lockfiles—no more blind spots between teams.
Auditable risk scores
Every update is scored with CVE severity, EPSS, reachability, and exploit signals—transparent weights you can defend in an audit.
AI prioritization
An LLM layer re-ranks with service context, owners, and policies. Explains why #1 is #1—without replacing the base score.
Policy engine
Auto-suppress transitive medium noise, block suppress on KEV, cap open PRs per repo. Rules you can toggle and audit.
12 ecosystems, one queue
npm, PyPI, Maven, Go, RubyGems, NuGet, crates.io, Docker, Helm, Terraform, Homebrew, and OS packages in a single view.
Safe upgrade PRs
Open single or group PRs, apply AI suggestions in one click, with CI status and owner badges on every row.
Email & Slack digests
Action-plan digests ranked by effective priority. Slack Block Kit preview today—webhook adapter when you go live.
SBOM & audit-ready
Export CycloneDX, findings CSV, and compliance JSON. Full audit log of scans, AI, policies, and digests.
How it works
From connect to digest in one continuous loop
Same path as the live demo: no slideware, no fake dashboards.
- 01
Connect your repos
Install the GitHub App (demo catalog today). Import private or public repos under plan limits.
- 02
Scan every layer
Lockfiles and manifests feed a multi-source advisory corpus—GHSA + OSV fixtures offline, live feeds via adapters.
- 03
Score + policy
Transparent F05 risk (0–100), then deterministic policies: auto-suppress noise, KEV requires an upgrade PR.
- 04
AI prioritize
F21 re-ranks with owners and context. Suggested actions: open PR, group, suppress, wait—always explainable.
- 05
Apply & digest
One-click Apply AI, group PRs, email + Slack digests. Audit trail for every action.
Risk you can audit. Priority your team can act on.
Stackpulse adds an LLM layer above the transparent risk score—not instead of it. Structured outputs, citations from your inventory, and human-or-policy final say.
How priority is built
F05 → F21- 1
Deterministic risk (0–100)
Severity, EPSS, exploit signals, reachability, direct deps, blast radius.
- 2
Context pack
Repo, owners, layer, policies, open PRs—metadata only, not your full source tree.
- 3
LLM delta + rationale
Validated JSON: priority adjustment, suggested action, citations. Low confidence falls back to base score.
- 4
You decide — one click
Apply AI opens PRs, groups packages, or suppresses with reason. Full audit trail.
The model never invents CVEs, never claims “not vulnerable,” and never executes package managers. Matching stays on OSV/semver; the PR worker stays sandboxed.
Auditable score first
CVSS, EPSS, KEV, and blast radius stay deterministic. The model never replaces the risk formula—it explains and adjusts on top.
Context-aware priority
Re-rank with service owners, internet-facing paths, freeze windows, and open PR limits—so #1 is what your team should do next.
Digests & PR copy
Weekly action digests for Slack and email, plus upgrade PR bodies with test plans and breaking-change notes.
Remediation plans
Group patches into safe PR batches under your policies. Suggest suppress with reason and expiry—never silent ignore.
Pricing
Simple plans that scale with your stack
Start free with full risk visibility. Unlock AI prioritization and automation on Team.
Starter
For side projects and open source maintainers.
$0forever- 3 private repositories
- Daily scans + risk scores
- Severity + CVE details
- Email digests
- Community support
- Most popular
Team
For product and platform teams shipping weekly.
$49/seat/mo- Unlimited private repos
- Continuous scanning
- AI prioritization + digests
- Auto upgrade PRs
- Slack + webhook alerts
- SBOM export + SSO
- Priority support
Enterprise
For regulated orgs with strict audit requirements.
Custom- Everything in Team
- Private / VPC AI options
- Custom policy engine
- On-prem / VPC deploy
- SLA + advanced audit logging
- Invoice billing
Customers
Teams sleep better knowing the stack is watched
“We went from a quarterly dependency fire-drill to a calm weekly queue. Critical CVEs land in Slack with context—not just a CVE ID.”
“Stackpulse is the first tool that told us which lodash upgrade actually mattered versus which ones were noise. Our MTTR on advisories dropped 60%.”
“The severity scoring plus auto PRs means our junior engineers can ship safe upgrades without a security review for every patch.”
Know what to fix before attackers do
Join the waitlist or explore the product demo—risk-ranked queue, findings, and the AI prioritization story on the landing path.
Free for open source. Auditable scores. AI that cites your inventory—not the open web.