Overview
Posture overview
Posture score, severity mix, and the top of the queue.

Perpensa inventories nine shipped parser families, matches advisories, and ranks the resulting findings and update candidates—so AppSec and platform share one review queue.
No credit card. Deterministic scoring always on—AI is explainable and optional.

Parser families shipped in this version
Product
Current captures of the posture overview, risk-ranked queue, and matched findings. Sign in to open those screens in your workspace.
Try for freeOverview
Posture score, severity mix, and the top of the queue.

Queue
Risk-ranked remediations with KEV and exploit signals.


Queue and detail stay readable at ~390px. Primary actions stay thumb-friendly so on-call can act without a laptop.
Try for freeFindings
Triage open advisories with KEV, exploit, and EPSS signals.

Risk over volume
Renovate and Dependabot keep dependencies fresh. Perpensa tells you which findings and update candidates deserve review, why, and what to do first—with a shared queue and evidence for AppSec.
A KEV-listed or high-exploit-probability finding before forty hygiene patches. Deterministic score first—always auditable.
Renovate is excellent at automation. Perpensa is the triage layer AppSec and platform share.
Findings, digests, CycloneDX/SPDX exports, and an audit trail — prove you are watching, not only merging.
Opens / groups PRs to keep packages fresh
Ranks the queue by risk (CVE/severity, EPSS, KEV/public exploit, direct/transitive)
Noise is volume of bumps (tunable, still PR-centric)
Prioritised queue + digests; optional remote PR
Lives in each repo’s config
One org cockpit: findings, inventory, SBOM, policies
Needs write to open branches
Read-first scan; public watch without push rights
Works alongside Renovate. Keep the bot for cadence and automerge; use Perpensa as the risk brain — triage, digests, SBOM, and optional remote PRs on writable npm repos. Other ecosystems stay queued for review, and Perpensa does not claim to replace Renovate's ecosystem depth.
Features
Stop sorting by severity alone. Perpensa turns supported dependency evidence into a prioritized review queue—scored by risk, shaped by policy, optionally re-ranked by AI.
Parse npm, PyPI, Go, Maven/Gradle, Cargo, Composer, NuGet, and Bundler lock data, plus Dockerfile base-image references. Other package formats are not scanned yet.
Rank matched advisories with deterministic severity, EPSS, KEV/public-exploit, and direct/transitive inputs. Every factor remains visible.
Pro plans can re-rank from allowlisted inventory and advisory metadata. On failure, a deterministic heuristic delta is applied instead.
Configure transitive-medium suppression, KEV guardrails, alert floors, and an open-PR limit. Policy actions are recorded for review.
npm and compatible JS lockfiles, PyPI lock and requirement files, Go modules, Maven/Gradle, Cargo.lock, composer.lock / composer.json, NuGet lock/csproj, Gemfile.lock, and Dockerfile FROM images.
With VCS write access, open a remote PR that applies the recommended npm bump. Other ecosystems stay in the review queue.
Build ranked email and Slack previews. Delivery requires a configured provider or per-org webhook; scheduled multi-tenant Slack remains store-only.
Export CycloneDX or SPDX SBOMs, findings and updates CSV, and a compliance bundle. Scan, AI, policy, and digest actions produce audit events.
How it works
Connect repositories, scan supported manifests, then review the queue, apply policy, and preview delivery on your own workspace.
Connect GitHub, GitLab, Bitbucket, Forgejo, or Gitea credentials. Public GitHub watches stay read-only.
Supported lockfiles, manifests, and Dockerfile FROM lines feed OSV matching.
Transparent risk score (0–100), then deterministic policies such as suppression floors and a KEV suppression guardrail.
Optional AI re-ranks allowlisted update and finding metadata. Suggested actions remain explicit and auditable.
Leave advice unapplied or ignore it, create a remote PR when configured, and preview or deliver digests through configured channels.
Perpensa adds an LLM layer above the transparent risk score—not instead of it. Validated output structure, allowlisted inventory context, and human-or-policy final say.
How priority is built
Deterministic risk (0–100)
Severity, EPSS, KEV/public exploit, and direct/transitive dependency status.
Context pack
Package, versions, advisory facts, and related findings—metadata only, not your source tree.
LLM delta + rationale
Validated JSON: priority adjustment, suggested action, citations. Low-confidence output stays advice for human review; on model failure, a deterministic heuristic delta is used.
You decide — one click
Applying a suggestion can request a remote PR or suppress with a reason. Both paths are audited.
Model output is validated JSON with structured citations. Vulnerability matching remains independent and uses OSV/semver; requested actions are re-checked against their own authorization and policy gates.
Pricing
Monthly price per organization. Start free, then pick the pack that matches your seats and repos.
For someone trying the queue on a few repos.
For a serious operator or a small company.
For a larger account that needs several people on one tenant.
Shipped workflow
Shared triage
Deterministic score + optional AI delta
Review matched advisories in one risk-ranked queue instead of treating every version bump as equally urgent.
Conditional delivery
Stored previews remain visible in-product
Generate email or Slack previews, then deliver only when the corresponding provider or per-org webhook is configured.
Explicit handoff
npm PRs apply the recommended bump
Open a remote PR on a writable npm repo when credentials exist. Other ecosystems stay queued for the team to change and verify.
Sign in with GitHub to open a workspace—risk-ranked queue, findings, exports, policies, and optional AI prioritization.
Try for freeAuditable scores. Optional AI uses allowlisted inventory and advisory metadata—not the open web.