polyfill.io was silently hijacked in June 2024, serving malicious code to 100,000+ websites. Your CVE scanner missed it.

OSPulse

The dependency that starts
your 24-hour clock
won't warn you first.

Under the EU Cyber Resilience Act, an actively exploited dependency puts you on a 24-hour reporting deadline — and the fastest trigger produces no CVE at all. OSPulse catches it, and records when you knew.

ospulse — supply-chain-threat-feed
14:07:03[COMPROMISED]polyfill.ioDomain hijacked · 100,000+ sites affected
14:07:04[MALICIOUS]event-streamBackdoor injected · 2M weekly downloads
14:07:05[BACKDOORED]xz-utilsNation-state attack · CVE-2024-3094
14:07:06[HIJACKED]ua-parser-jsMaintainer takeover · 8M weekly downloads
14:07:07[SABOTAGED]colors.jsAuthor protest · intentional infinite loop
14:07:08[WEAPONISED]node-ipcWiper malware triggered by geolocation
New

Meet Article 14 Signal — the module that watches the clock.

An alert the moment a dependency you rely on becomes actively exploited, a timestamped record of when that signal reached you — the one fact that determines Article 14 liability — and a pre-drafted submission payload. Filing to the ENISA Single Reporting Platform stays manual; there is no API, and we would rather say so than promise otherwise.

days until reporting duties begin · 11 September 2026
New

Google is migrating off RSA and ECC by 2029. Do you know where all of yours are?

The Quantum Proofing Scanner finds every legacy certificate and outdated crypto library across your codebase and dependency tree — before the deadlines find you.

Free

Scan your dependencies for free — no account required.

A local, no-account CLI that emits a CycloneDX or SPDX SBOM and an exploitation-first risk read from public CISA KEV + OSV intelligence — offline-capable. The SBOM carries the CISA Minimum Elements; the risk read never calls a component “safe” on no signal. Detection and drafts only — it does not make you compliant.

OSPulse.Cli on NuGetOSPulse CLI GitHub releaseOSPulse VS Code extension
$ dotnet tool install --global OSPulse.Cli
Download binaries →VS Code extension
0%
Increase in supply chain attacks (2024 YoY)
0 mo
Avg. time to detect a compromised package
0%
Critical vulns originate in transitive deps
0+
Open-source packages in a typical enterprise app

Traditional scanners answer yesterday's questions.

CVEs are published after the damage is done. OSPulse watches the signals that come before.

Dependabot / Snyk

  • Is there a known CVE?
  • Is this version in the vulnerable range?
  • Is the licence allowed?
  • Is there a newer version?

OSPulse

  • Is this package being abandoned right now?
  • Have its maintainers gone silent?
  • Is this package in a live breach feed?
  • Has the source repo been hijacked?
  • Is the release cadence collapsing?
  • Which of our apps breaks if this fails?
  • What should we replace, fork, pin, or escalate?

Intelligence your CVE scanner doesn't have.

Exposure AlertingNew

It tells you. You don’t have to be looking.

Detecting an exploited dependency and saying nothing until someone logs in defeats the point — especially under a 24-hour reporting clock that can start at 3am on a Sunday. When a package you depend on enters CISA KEV, or a new Critical or High advisory hits the version you actually run, OSPulse emails your administrators within one detection cycle.

  • Alerts within about an hour of the advisory landing
  • Names the package, advisory, severity and affected repositories
  • On by default — no settings screen required
  • Medium and Low collapse into one daily digest, not a flood
  • Slack, Microsoft Teams and outbound webhook when you want them
  • Alerts once — hourly re-detection never re-alerts
Compromise IntelligenceWorld-first feature

Supply chain attacks caught in real time

OSPulse monitors OSV.dev, npm security advisories, PyPI malware reports, Socket.dev threat feeds, Sonatype intelligence, CISA KEV, and more — cross-referenced against your actual dependency tree. When a package you depend on appears in a breach feed, you know within minutes.

  • Breach feed monitoring across 8+ intelligence sources
  • Account takeover and maintainer hijack detection
  • Typosquatting and dependency confusion alerts
  • Malicious code injection pattern matching
  • Blast radius: which of your apps are affected
  • Immediate remediation playbook generated
Drift Detection

Detect abandoned packages before they become incidents

Traditional scanners wait for a CVE. OSPulse tracks commit velocity, release cadence, maintainer activity, issue responsiveness, and bus factor — flagging packages that are quietly going dark weeks or months before a security incident.

  • Commit velocity collapse detection (>70% drop)
  • Maintainer activity monitoring (90-day and 365-day windows)
  • Bus factor estimation — single-maintainer risk alerts
  • Release cadence deterioration scoring
  • Issue and PR backlog growth analysis
  • Package abandonment prediction with confidence score
Health Scoring

Every dependency. A single score. Full evidence.

Each package receives a 0–100 health score with a confidence rating and complete evidence trail. Ten weighted dimensions — maintainer health, activity, release cadence, vulnerability exposure, licence risk, provenance, and more.

  • Health score 0–100 across 10 weighted dimensions
  • Confidence score flags low-evidence packages
  • Weights configurable per tenant policy
  • Full evidence trail for every score
  • Historical score trend charts
  • Risk level: Minimal / Low / Medium / High / Critical

Everything else you'd expect from an enterprise platform

⚙️

Policy Engine

Define policies at tenant, workspace, team, or repo level. Enforce in CI/CD with pass/fail gates.

🔗

CI/CD Integration

GitHub Actions, Azure DevOps pipelines, GitLab CI. Pull request checks with actionable comments.

📊

Executive Dashboards

Leadership-ready risk summaries alongside raw evidence. The right view for every stakeholder.

🤖

AI Risk Summaries

Plain-English explanations of why a package is risky, grounded in deterministic evidence. Auditable.

📄

SBOM Import / Export

CycloneDX and SPDX support. Import existing SBOMs, export for compliance and procurement.

🔐

Enterprise Auth

SSO with OIDC and SAML, SCIM, MFA, RBAC with 11 role types, full audit trail.

🔔

Smart Alerting

Route alerts to Slack, Teams, email, or webhooks. 20 alert types with suppression controls.

📋

Compliance Reports

ISO 27001, SOC 2, Cyber Essentials Plus. Exportable evidence with approval history and audit trail.

🌐

10+ Ecosystems

npm, NuGet, PyPI, Maven, Go, Cargo, RubyGems, Composer, Docker, GitHub Actions.

Integrates with your existing stack

GitHubGitLabAzure DevOpsBitbucketJiraAzure BoardsLinearSlackTeamsnpmNuGetPyPIMavenGoCargoDocker

One plan. Everything in it.

£2,988/year plus VAT at the founding rate, locked for life and limited to 25 places.

You are buying a reporting deadline, and a deadline does not come in sizes.

See what's included

Stop waiting for a CVE.
Get ahead of the risk.

Join engineering and security teams who are already detecting dependency drift and supply chain compromise before it becomes a production incident.