Pragma Core scans every dependency in every repository against a comprehensive vulnerability database. You get real-time alerts on vulnerable packages, clear upgrade paths, and a single view across your entire software supply chain.
The platform parses your dependency manifests, checks every package against known vulnerability data, and surfaces issues with everything you need to act.
A real engineering org has dependencies in several ecosystems and a long tail of CVE alerts at any given moment. Here is what the dashboard view collapses that into.
Counts pulled across every repository in a single workspace, grouped by package manager. Hover any bar to see how the severity mix breaks down.
Ranked by CVSS, with a clear fix path. The "in repos" column tells you how many repositories pull in the same vulnerable version, which is usually the first question that comes up in triage.
| Package | Severity | CVE | Fixed in | In repos |
|---|---|---|---|---|
| [email protected] | 9.8 | CVE-2021-23337 | 4.17.21 | 7 |
| [email protected] | 8.6 | CVE-2023-31047 | 3.2.19 | 3 |
| [email protected] | 10.0 | CVE-2021-44228 | 2.17.1 | 2 |
| [email protected] | 5.6 | CVE-2022-24785 | 2.29.4 | 9 |
| [email protected] | 7.5 | CVE-2022-0778 | 1.1.1n | 4 |
Connect your repositories and get instant visibility into every vulnerable package across your stack.
Choose which categories you are happy to allow. You can change your mind at any time using the Cookie settings link in the footer.