Open-source dependency health.
Evidence first. Always.
OSPulse continuously analyses your repositories, packages, and dependency tree — surfacing risk that matters, with the evidence to back every claim.
Google is migrating off RSA and ECC by 2029. NIST deprecates them in 2030. Do you know where all of yours are?
The Quantum Proofing Scanner finds every legacy certificate and outdated crypto library across your codebase and dependency tree — before the deadlines find you.
Post-quantum migration isn’t a future problem anymore. In March 2026, Google committed to completing its own migration to post-quantum cryptography by 2029 — a full year ahead of NIST’s deprecation date — and urged the rest of the industry to follow. Regulators on both sides of the Atlantic have set hard dates. And “harvest now, decrypt later” means data stolen today can be decrypted the day quantum hardware catches up.
The first step every framework agrees on: inventory. You can’t migrate cryptography you can’t find. OSPulse scans your repositories, dependency trees, and certificates to surface RSA, ECC, and other quantum-vulnerable algorithms wherever they hide — in your code, in your transitive dependencies, and in the certificate estate you forgot you had.
Legacy certificate discovery — find every RSA and ECC certificate across your estate, with expiry and algorithm details, before 47-day certificate lifespans make manual tracking impossible.
Crypto library detection — flag outdated and quantum-vulnerable crypto libraries in your dependency tree, including transitive dependencies your CVE scanner never looks at.
CI/CD gate — fail builds that introduce new quantum-vulnerable crypto, so your exposure shrinks instead of growing.
Readiness reporting — a PQC readiness view you can hand to a CISO, an auditor, or a customer security questionnaire.
The deadline stack
- Jan 2027NSA CNSA 2.0 prohibits new acquisitions into national security systems that don’t support PQC.
- 2029Google’s self-imposed deadline to complete its PQC migration across its entire infrastructure.
- 2029CA/Browser Forum’s 47-day maximum SSL/TLS certificate lifespan takes full effect — a 12× increase in renewal frequency.
- 2030NIST deprecates legacy algorithms (RSA, ECC); US executive order deadline for federal high-value systems, extending to contractors and vendors; EU deadline for critical infrastructure.
- 2033Quantum-resistant encryption becomes the exclusive standard for US national security systems.
- 2035NIST disallows legacy algorithms entirely.
Migration takes years. Discovery is step one — and it starts with a scan.
How OSPulse works
Connect
Install the GitHub App or connect GitLab / Azure DevOps / Bitbucket. Select repositories in minutes.
Scan
OSPulse parses manifests, lock files, SBOMs, and container images. Resolves your full dependency tree.
Score
Every package receives a health score (0–100) across 10 dimensions, with confidence rating and evidence trail.
Act
Alerts in Slack, Teams, email. CI/CD gates on pull requests. Jira tickets. AI-generated remediation guidance.
A 0–100 score for every dependency. Full evidence for every score.
OSPulse calculates a health score across 10 weighted dimensions. The weights are configurable per tenant policy. Every score ships with a confidence rating — when evidence is missing, the score is flagged as uncertain, not silently assumed safe.
Risk levels map to: Minimal (90–100), Low (75–89), Medium (55–74), High (35–54), Critical (0–34).
Scans every manifest you have
From package.json to Dockerfile to Terraform lock files.
Ready to scan your first repository?
Setup takes under 10 minutes. First scan results in under 5.
