All features Supply chain security

Security workflow

Available now

Turn dependency advisories into upgrade decisions.

Winfunc scans supported repository dependency data with osv-scanner, enriches each result from the OSV API, and preserves package, version, severity, affected-range, and reference context. The dashboard turns available fix data into ecosystem-specific upgrade guidance and recommends a rescan when OSV does not name a fixed version.

Supply chain securityAvailable now
01Repository dependencies
02OSV enrichment
03upgrade and rescan
Conceptual workflow · scope and review stay visible

The problem

Security work should end in a decision, not another queue.

A package identifier and severity score are not enough to plan remediation. Teams need to know which repository contains the dependency, what OSV reports, whether a fixed version exists, and how to make and verify the upgrade in the package ecosystem they use.

WorkflowRepository dependencies → OSV enrichment → upgrade and rescan

How it works

From scope to an engineering decision.

Connect an authorized repository with supported dependency files and identify the engineering owners who will assess and apply package upgrades.

  1. 01
    Scope

    Scan supported repository dependency files with osv-scanner

  2. 02
    Investigate

    Enrich detected vulnerabilities with current OSV advisory details

  3. 03
    Investigate

    Review affected versions, severity, references, and available fixes

  4. 04
    Review

    Apply the ecosystem-specific upgrade path and rescan the repository

Review-ready output

What your team gets.

Repository-scoped OSV findings

Affected and fixed-version context

Upgrade guidance with a rescan step

Built for handoff

Evidence your team can inspect.

Keep the reviewed scope, supporting evidence, uncertainty, and next action together so security and engineering can make the same decision from the same context.

Measure the workflow

Track open dependency findings, findings with a named fixed version, upgrade lead time, and the share closed by a clean follow-up scan.

Why it matters

Reduce time spent translating advisory records into concrete, verifiable dependency upgrades.

Scope & limits

Coverage follows osv-scanner and OSV data. It does not prove application logic, build provenance, or runtime exposure is secure.