We see every repo and server you run.
You can't secure what you can't see — so the first job is a complete, always-current picture of your stack.
- Install the GitHub App on the repositories you ship from. We read your lockfiles — composer.lock, package-lock.json, pnpm-lock.yaml, yarn.lock — so we know the exact versions you actually run.
- Install the read-only sensor on your servers. It reports the OS packages your machine already knows about, whether a reboot is pending, and whether unattended upgrades are even on.
- From then on, "what are we running?" has a real answer instead of a guess.