Risk over volume · not another PR bot

Parse supported manifests. Review what matters first.

Perpensa inventories five shipped parser families, matches advisories, and ranks the resulting findings and update candidates—so AppSec and platform share one review queue.

No credit card. Deterministic scoring always on—AI is explainable and optional.

GitHub, GitLab, Bitbucket, Forgejo/Giteanpm, PyPI, Go, Maven, DockerOSV + EPSS/KEV + SBOM
illustrative queue · risk + optional AI priority
AI on

Prioritized updates

Base risk + AI delta

  • express
    Critical
    +4
    npm

    AI: direct dependency · KEV · review first

    CVE-2024-43796

    4.18.24.21.2
    risk 96100Review
  • django
    Critical
    +2
    pypi

    AI: direct dependency · public exploit signal

    CVE-2024-45230

    4.2.114.2.16
    risk 9193Review
  • lodash
    High
    -12
    npm

    AI: transitive dependency · lower priority than direct criticals

    CVE-2021-23337

    4.17.204.17.21
    risk 7866Wait
  • react
    Low
    npm

    Hygiene patch — no CVE · schedule with next release

    18.2.018.3.1
    risk 2222Batch
  • junit:junit
    Info
    -8
    maven

    AI: no matched advisory · schedule after security work

    4.12.04.13.2
    risk 1810Defer

Parser families shipped in this version

  • npm
  • PyPI
  • Dockerfile FROM
  • Go modules
  • Maven / Gradle

Interactive demo

Real product paths, labeled demo data

Run a fixture scan, apply policies and optional AI, request an evidence-note PR on a writable remote, then preview or deliver a digest when a provider is configured. Switch between Acme (Team) and Northstar (Starter) in the app sidebar — isolation is real; the repositories and findings are sample data.

Open the product
  1. 01

    Scan

    Fixture parser + advisory evidence

  2. 02

    Policy

    Suppression rules · KEV guardrail

  3. 03

    AI rank

    F21 on top of F05 risk score

  4. 04

    Apply

    Suggestion · suppress · PR note

  5. 05

    Digest

    Stored preview · optional delivery

  6. 06

    Orgs

    Switch demo tenants in-app

Product screenshots

See the queue your team will live in

Current sample-data captures of the overview, risk-ranked queue, and matched findings. Click any shot to open that screen in the demo.

Open live demo
app.perpensa.dev
Perpensa posture overview with severity trend chart and top of queue

Posture overview

Criticals, highs, and a 7-day trend at a glance.

Perpensa update queue on a mobile viewport

Mobile-ready triage

Queue and detail stay readable at ~390px. Primary actions stay thumb-friendly so on-call can act without a laptop.

Try the queue

Risk over volume

Not another upgrade bot

Renovate and Dependabot keep dependencies fresh. Perpensa tells you which findings and update candidates deserve review, why, and what to do first—with a shared queue and evidence for AppSec.

Risk over volume

A KEV-listed or high-exploit-probability finding before forty hygiene patches. Deterministic score first—always auditable.

Brain, not another arm

Renovate is excellent at automation. Perpensa is the triage layer AppSec and platform share.

Evidence, not just bumps

Findings, digests, CycloneDX/SPDX exports, and an audit trail — prove you are watching, not only merging.

Upgrade bots
Perpensa
  • Opens / groups PRs to keep packages fresh

    Ranks the queue by risk (CVE/severity, EPSS, KEV/public exploit, direct/transitive)

  • Noise is volume of bumps (tunable, still PR-centric)

    Prioritised queue + digests; optional evidence-note PR

  • Lives in each repo’s config

    One org cockpit: findings, inventory, SBOM, policies

  • Needs write to open branches

    Read-first scan; public watch without push rights

Works alongside Renovate. Keep the bot for cadence and automerge; use Perpensa as the risk brain — triage, digests, SBOM, and optional evidence-note PRs on writable repos. Perpensa does not edit manifests today, and does not claim to replace Renovate's ecosystem depth.

Features

Built for teams who can't afford surprise outages

Stop sorting by severity alone. Perpensa turns supported dependency evidence into a prioritized review queue—scored by risk, shaped by policy, optionally re-ranked by AI.

  • Supported manifest inventory

    Parse npm, PyPI, Go, Maven/Gradle lock data, and Dockerfile base-image references. Other package formats are not scanned yet.

  • Auditable risk scores

    Rank matched advisories with deterministic severity, EPSS, KEV/public-exploit, and direct/transitive inputs. Every factor remains visible.

  • AI prioritization

    Team plans can re-rank from allowlisted inventory and advisory metadata. On failure, a deterministic heuristic delta is applied instead.

  • Policy engine

    Configure transitive-medium suppression, KEV guardrails, alert floors, and an open-PR limit. Policy actions are recorded for review.

  • Five parser families, one queue

    npm and compatible JS lockfiles, PyPI lock and requirement files, Go modules, Maven/Gradle lock data, and Dockerfile FROM images.

  • Evidence-note PR workflow

    With VCS write access, open a remote PR containing a .stackpulse evidence note. It does not edit manifests or run a package manager; grouped notes are GitHub-only today.

  • Digest previews and delivery

    Build ranked email and Slack previews. Delivery requires a configured provider or per-org webhook; scheduled multi-tenant Slack remains store-only.

  • SBOM & audit-ready

    Export CycloneDX or SPDX SBOMs, findings and updates CSV, and a compliance bundle. Scan, AI, policy, and digest actions produce audit events.

How it works

From connect to digest in one continuous loop

The demo uses labeled sample data and fixture scans while exercising the real queue, policy, export, and delivery-preview paths.

  1. 01

    Connect your repos

    Connect GitHub, GitLab, Bitbucket, Forgejo, or Gitea credentials. Public GitHub watches stay read-only.

  2. 02

    Parse supported files

    Supported lockfiles, manifests, and Dockerfile FROM lines feed OSV matching, with fixture fallback for the demo.

  3. 03

    Score + policy

    Transparent F05 risk (0–100), then deterministic policies such as suppression floors and a KEV suppression guardrail.

  4. 04

    AI prioritize

    Optional F21 re-ranks allowlisted update and finding metadata. Suggested actions remain explicit and auditable.

  5. 05

    Review & notify

    Leave advice unapplied or ignore it, create an evidence-note PR when configured, and preview or deliver digests through configured channels.

AI copilot

Risk you can audit. Priority your team can act on.

Perpensa adds an LLM layer above the transparent risk score—not instead of it. Validated output structure, allowlisted inventory context, and human-or-policy final say.

How priority is built

F05 → F21
  1. 1

    Deterministic risk (0–100)

    Severity, EPSS, KEV/public exploit, and direct/transitive dependency status.

  2. 2

    Context pack

    Package, versions, advisory facts, and related findings—metadata only, not your source tree.

  3. 3

    LLM delta + rationale

    Validated JSON: priority adjustment, suggested action, citations. Low-confidence output stays advice for human review; on model failure, a deterministic heuristic delta is used.

  4. 4

    You decide — one click

    Applying a suggestion can request an evidence-note PR or suppress with a reason. Both paths are audited.

Model output is validated JSON with structured citations. Vulnerability matching remains independent and uses OSV/semver; requested actions are re-checked against their own authorization and policy gates.

  • Auditable score first

    Severity, EPSS, KEV/public-exploit, and direct/transitive inputs stay deterministic. The model never replaces the risk formula.

  • Context-aware priority

    Re-rank from allowlisted inventory, update, and advisory metadata. No repository source tree is sent to the model.

  • Structured suggestions

    Return a validated priority delta, rationale, suggested action, and citations. Digests can use the resulting effective priority.

  • Human-controlled actions

    Apply a suggestion explicitly or leave it as advice. Suppression requires a reason, and PR creation remains a separate audited action.

Pricing

Product plan gates, without a billing claim

The plan and entitlement shell is implemented; billing checkout is not connected yet.

  • Starter

    For side projects and open source maintainers.

    Freeplan shell
    • 3 repositories (VCS + public watches)
    • Five shipped parser families
    • Deterministic risk scores
    • Email digest preview or configured delivery
    • CycloneDX, SPDX, and CSV exports
    Explore the demo
  • Team feature gate

    Team

    For product and platform teams shipping weekly.

    Pilotno checkout yet
    • Unlimited repositories
    • Manual and webhook scan jobs
    • Optional AI prioritization
    • Policy controls and audit events
    • Evidence-note PRs with VCS write access
    • Configured email, Slack, and webhook delivery
    • CycloneDX, SPDX, and CSV exports
    Explore the demo
  • Enterprise

    For teams evaluating the self-managed deployment path.

    Self-hostDocker path
    • Everything in Team
    • Node-server Docker build
    • Organization roles and audit events
    • Encrypted per-org integration secrets
    • Policy YAML import and export
    • Self-managed runtime controls
    Review the demo

Shipped workflow

What the current product helps teams review

  • Review matched advisories in one risk-ranked queue instead of treating every version bump as equally urgent.

    Shared triage

    Deterministic score + optional AI delta

  • Generate email or Slack previews, then deliver only when the corresponding provider or per-org webhook is configured.

    Conditional delivery

    Stored previews remain visible in-product

  • Open a remote evidence-note PR when write credentials exist, while leaving the actual dependency edit and verification to the team.

    Explicit handoff

    No package-manager execution or manifest edit

Explore the evidence before choosing an action

Explore the sample-data demo—risk-ranked queue, findings, exports, policies, and optional AI prioritization.

Explore the live demo

Auditable scores. Optional AI uses allowlisted inventory and advisory metadata—not the open web.