Choose the coverage your stack needs.
For your everyday dependenciesFree
$0 USD · no subscription
Understand your stack and follow the packages that matter.
- 25 packages in your watchlist
- Search and assess public packages across 7 ecosystems
- Public project manifest checks
- Email alerts and weekly digest
- Live feed, supply-chain news and repository trendlines
Get started free →
More coverage · private analysisPro
$6 USD / month
Or $60 USD / year — save $12 versus monthly billing.
- Everything in Free, with 1,000 watched packages
- Slack and Discord alerts, plus a private watchlist feed
- 5 private GitHub repositories · read-only root npm analysis; connection setup required
- 5 integration sources · private SBOM imports, CI uploads and JFrog / Xray connectors
- Hourly connector refreshes and encrypted private inventories
View Pro in your dashboard →
Planned · not available for purchasePremium
TBA pricing not set
For when a dependency needs a fix and upgrading alone is not enough.
- Planned: Pro features plus repository-aware AI patch proposals
- Proposed dependency, configuration or source-code changes
- Suggested regression tests and a validation report
- Reviewable patches, with your approval before publication
- Requires access to the relevant project; usage limits are still being defined
Explore planned Premium →
Compare every feature and limit →
Compare features and limits
| Feature | Free | Pro | Premium · planned |
|---|
| Public package search, assessments and project checks | Included | Included | Planned: included |
|---|
| Supported package ecosystems | npm, PyPI, Cargo, Go, Maven, NuGet, RubyGems | All 7 | Planned: all 7 |
|---|
| Unique watched packages | 25 | 1,000 | Not set yet |
|---|
| Email alerts and weekly digest | Included | Included | Planned: included |
|---|
| Live feed, supply-chain news and trendlines | Included | Included | Planned: included |
|---|
| Slack / Discord and private watchlist feed | Not included | Included | Planned: included |
|---|
| Private GitHub analysis | Not included | 5 repositories; root package.json + package-lock.json; App setup required | Planned: broader project context for patching |
|---|
| Private GitHub analysis allowance | Not included | 20 analyses per rolling 24 hours; up to 500 direct dependencies per analysis | Not set yet |
|---|
| Platform integration sources | Not included | 5 sources, separate from GitHub repositories | Planned: included; final limits not set |
|---|
| SBOM formats | Not included | CycloneDX JSON 1.4–1.6; SPDX JSON 2.2–2.3 | Planned: included |
|---|
| Direct vendor connections | Not included | Artifactory inventory; Xray artifact findings (read-only) | Planned: included |
|---|
| Wiz, GitLab, Snyk, Sonatype and other platforms | Public news where available | Supported SBOM exports / CI uploads; no native tenant API connection yet | Planned: included |
|---|
| Integration inventory limits | Not included | 2,000 components; 2,000 supplied findings; 2 MiB JSON per source | Not set yet |
|---|
| Integration upload / manual sync allowance | Not included | 20 actions per rolling 24 hours; hourly scheduled connector refreshes | Not set yet |
|---|
| Private data retention | Not applicable | GitHub reports: 30 days; integration sources and credentials: expire 30 days after creation | Not set yet |
|---|
| Repository-aware AI patch generation | Not included | Not included | Planned; not live |
|---|
Premium: a proposed fix, with evidence.
Premium is being designed for vulnerable or end-of-life dependencies where there is no straightforward upgrade. With access to the relevant repository, the proposed service would suggest a patch and show what was tested, what passed and what still needs review.
AI patch generation is not currently available in any plan. Premium pricing, usage allowances and launch timing are not set. There is no Premium checkout, and upgrading to Pro does not enable patch generation.
Generated patches would require human review. They would not automatically merge or deploy, or guarantee that a vulnerability is resolved.
What to know before choosing Pro
Private GitHub analysis currently covers root npm manifests and lockfiles, not full project code or every ecosystem. Connection availability is shown before you authorize GitHub.
Integrations import existing inventory and findings; they do not run a new vendor security scan. Xray requires an eligible vendor subscription and a completed scan. Direct JFrog connectors still need validation with your tenant. Provider scan times and successful sync times are shown separately.
You can manage your subscription from your dashboard. Private data stays out of the public crawl queue, and you can delete retained private sources after downgrading.
Open plan and billing settings →