Risk score · policies · AI · digests

Scan your stack. Ship the fixes that actually matter.

Stackpulse inventories your dependencies, ranks updates with an auditable risk score, applies policy, then reorders work with an AI copilot—so security and platform ship the same queue.

No credit card. Deterministic scoring always on—AI is explainable and optional.

GitHub, GitLab, Bitbucket12 package ecosystemsCVE + SBOM + AI priority
stackpulse queue · risk + AI priority
AI on

Prioritized updates

Base risk + AI delta

  • express
    Critical
    +4
    npm

    AI: edge-facing API · KEV · open PR this week

    CVE-2024-43796

    4.18.24.21.2
    risk 96100Open PR
  • django
    Critical
    +2
    pypi

    AI: ml-pipeline prod · public exploit signal

    CVE-2024-45230

    4.2.114.2.16
    risk 9193Open PR
  • lodash
    High
    -12
    npm

    AI: transitive · unreachable template path → lower priority

    CVE-2021-23337

    4.17.204.17.21
    risk 7866Wait
  • react
    Low
    npm

    Hygiene patch — no CVE · schedule with next release

    18.2.018.3.1
    risk 2222Batch
  • hashicorp/aws
    Info
    -8
    terraform

    AI: breaking provider schema · freeze window active

    5.40.05.72.1
    risk 1810Defer

Trusted by engineering teams shipping at scale

  • Northwind Labs
  • Helix Cloud
  • ParcelOps
  • Orbit Finance
  • Cascade Health
  • Vantage AI

Interactive demo

The full loop is live—not a mockup

Connect a catalog GitHub install, run a fixture scan, apply policies and AI, open group PRs, then ship digests. Switch between Acme (Team) and Northstar (Starter) in the app sidebar — isolation is real. Adapters flip via env flags.

Open the product
  1. 01

    Scan

    npm lockfile + multi-source advisories

  2. 02

    Policy

    Auto-suppress noise · KEV requires PR

  3. 03

    AI rank

    F21 on top of F05 risk score

  4. 04

    Apply

    One-click PR / suppress / group

  5. 05

    Digest

    Email + Slack Block Kit preview

  6. 06

    Orgs

    Switch demo tenants in-app

Product screenshots

See the queue your team will live in

Real captures from the interactive demo—overview, risk-ranked updates, findings, and connected repos. Click any shot to open that screen.

Open live demo
app.stackpulse.dev
Stackpulse posture overview with severity trend chart and top of queue

Posture overview

Criticals, highs, and a 7-day trend at a glance.

Stackpulse update queue on a mobile viewport

Mobile-ready triage

Queue and detail stay readable at ~390px. Primary actions stay thumb-friendly so on-call can act without a laptop.

Try the queue

Features

Built for teams who can't afford surprise outages

Stop chasing changelogs. Stackpulse turns dependency noise into a prioritized action plan—scored by risk, shaped by policy, sharpened by AI.

  • Full-stack inventory

    One scan covers application deps, container base images, IaC providers, and lockfiles—no more blind spots between teams.

  • Auditable risk scores

    Every update is scored with CVE severity, EPSS, reachability, and exploit signals—transparent weights you can defend in an audit.

  • AI prioritization

    An LLM layer re-ranks with service context, owners, and policies. Explains why #1 is #1—without replacing the base score.

  • Policy engine

    Auto-suppress transitive medium noise, block suppress on KEV, cap open PRs per repo. Rules you can toggle and audit.

  • 12 ecosystems, one queue

    npm, PyPI, Maven, Go, RubyGems, NuGet, crates.io, Docker, Helm, Terraform, Homebrew, and OS packages in a single view.

  • Safe upgrade PRs

    Open single or group PRs, apply AI suggestions in one click, with CI status and owner badges on every row.

  • Email & Slack digests

    Action-plan digests ranked by effective priority. Slack Block Kit preview today—webhook adapter when you go live.

  • SBOM & audit-ready

    Export CycloneDX, findings CSV, and compliance JSON. Full audit log of scans, AI, policies, and digests.

How it works

From connect to digest in one continuous loop

Same path as the live demo: no slideware, no fake dashboards.

  1. 01

    Connect your repos

    Install the GitHub App (demo catalog today). Import private or public repos under plan limits.

  2. 02

    Scan every layer

    Lockfiles and manifests feed a multi-source advisory corpus—GHSA + OSV fixtures offline, live feeds via adapters.

  3. 03

    Score + policy

    Transparent F05 risk (0–100), then deterministic policies: auto-suppress noise, KEV requires an upgrade PR.

  4. 04

    AI prioritize

    F21 re-ranks with owners and context. Suggested actions: open PR, group, suppress, wait—always explainable.

  5. 05

    Apply & digest

    One-click Apply AI, group PRs, email + Slack digests. Audit trail for every action.

AI copilot

Risk you can audit. Priority your team can act on.

Stackpulse adds an LLM layer above the transparent risk score—not instead of it. Structured outputs, citations from your inventory, and human-or-policy final say.

How priority is built

F05 → F21
  1. 1

    Deterministic risk (0–100)

    Severity, EPSS, exploit signals, reachability, direct deps, blast radius.

  2. 2

    Context pack

    Repo, owners, layer, policies, open PRs—metadata only, not your full source tree.

  3. 3

    LLM delta + rationale

    Validated JSON: priority adjustment, suggested action, citations. Low confidence falls back to base score.

  4. 4

    You decide — one click

    Apply AI opens PRs, groups packages, or suppresses with reason. Full audit trail.

The model never invents CVEs, never claims “not vulnerable,” and never executes package managers. Matching stays on OSV/semver; the PR worker stays sandboxed.

  • Auditable score first

    CVSS, EPSS, KEV, and blast radius stay deterministic. The model never replaces the risk formula—it explains and adjusts on top.

  • Context-aware priority

    Re-rank with service owners, internet-facing paths, freeze windows, and open PR limits—so #1 is what your team should do next.

  • Digests & PR copy

    Weekly action digests for Slack and email, plus upgrade PR bodies with test plans and breaking-change notes.

  • Remediation plans

    Group patches into safe PR batches under your policies. Suggest suppress with reason and expiry—never silent ignore.

Pricing

Simple plans that scale with your stack

Start free with full risk visibility. Unlock AI prioritization and automation on Team.

  • Starter

    For side projects and open source maintainers.

    $0forever
    • 3 private repositories
    • Daily scans + risk scores
    • Severity + CVE details
    • Email digests
    • Community support
    Start free
  • Most popular

    Team

    For product and platform teams shipping weekly.

    $49/seat/mo
    • Unlimited private repos
    • Continuous scanning
    • AI prioritization + digests
    • Auto upgrade PRs
    • Slack + webhook alerts
    • SBOM export + SSO
    • Priority support
    Start 14-day trial
  • Enterprise

    For regulated orgs with strict audit requirements.

    Custom
    • Everything in Team
    • Private / VPC AI options
    • Custom policy engine
    • On-prem / VPC deploy
    • SLA + advanced audit logging
    • Invoice billing
    Talk to sales

Customers

Teams sleep better knowing the stack is watched

  • We went from a quarterly dependency fire-drill to a calm weekly queue. Critical CVEs land in Slack with context—not just a CVE ID.

    Maya Chen

    Head of Platform, Helix Cloud

  • Stackpulse is the first tool that told us which lodash upgrade actually mattered versus which ones were noise. Our MTTR on advisories dropped 60%.

    Jordan Hale

    Staff Security Engineer, Orbit Finance

  • The severity scoring plus auto PRs means our junior engineers can ship safe upgrades without a security review for every patch.

    Priya Nair

    Engineering Manager, Cascade Health

Know what to fix before attackers do

Join the waitlist or explore the product demo—risk-ranked queue, findings, and the AI prioritization story on the landing path.

Free for open source. Auditable scores. AI that cites your inventory—not the open web.