Inside the radar

See what you run and prove you fixed it. The tour takes two minutes.

See

Know what you run

One live inventory across every project: what is installed, and where it runs.

Tracking 1,847 dependencies · 2 ecosystems · 12 projects · 9 vulnerable

NameVersionRelationshipEnvVulns
undiciNPM6.21.0DirectProd3
esbuildNPM0.27.7DirectDev
postcssNPM8.4.29TransitiveProd1
guzzlehttp/guzzleCOMPOSER7.9.2TransitiveProd

Why is this even in my app?

Trace any package back to the code that pulls it in. Diamond dependencies stop being a mystery.

How brace-expansion is required · via 3 paths (diamond dependency)

eslint@9.39.4direct@eslint/config-array@0.21.2minimatch@3.1.5brace-expansion@1.1.13
eslint-plugin-import@2.32.0directminimatch@3.1.5brace-expansion@1.1.13
eslint@9.39.4directminimatch@3.1.5brace-expansion@1.1.13

Preview

Debt, measured in days

Each dependency shows how far behind it runs, and for how long. A brand-new release cools down before it counts as debt. In preview: ask us to turn it on.

Freshness · ridgeline/api npm · Composer

undiciNPM6.21.0 7.3.01 major behind · 214 days
guzzlehttp/guzzleCOMPOSER7.9.2 7.10.11 minor behind · 38 days
esbuildNPM0.27.7 0.27.10cooling down · out 2 days
Triage

Advisories that know your org

An advisory arrives already matched to your projects, with the version that fixes each one. The rest never enters your queue.

semver: ReDoS in new Range() parsing

High severity 7.5Rarely exploitedFix availableCVE-2022-25883

Affected in your organization

ridgeline/api Transitive · Prod7.5.1 patch → 7.5.2
ridgeline/worker Transitive · Dev7.3.8 minor → 7.5.2
Prove

Prove you fix on time

Set fix deadlines once. Every exposure gets a clock, and the trend keeps the numbers an audit asks for.

Overdue 1Due soon 1On track 194% met target · 13 closed this window
semver 7.5.1ReDoS in new Range()CVE-2022-25883High 7.51 day overdue
glob-parent 5.1.1ReDoS in enclosure regexCVE-2020-28469High 7.5Due in 6 days
minimist 1.2.5Prototype pollutionCVE-2021-44906Critical 9.8Closed on time
Exposure points now42severity-weighted, across 15 open
Change over 90 days↓ 18 ptslower is better
Average time to close6.4 daysfirst confirmed to closed
Hear

Hear about it once

A new advisory in your stack pings the channel you chose, with the projects it affects. Everything else waits for the digest.

  • Slack
  • Discord
  • Email
# securityInstant alert · Tue 14:52

StackRadarAPP2:52 PM

New medium advisory · postcss 8.4.29

PostCSS line return parsing error · CVE-2023-44270

Affects ridgeline/api and ridgeline/web · View advisory

Connect

In your CI, both directions

One line in CI sends your lockfiles in, no repo access needed. PR checks gate the other way: a bad version gets a red check before it merges.

.github/workflows/stackradar.yml

- uses: actions/checkout@v7
- uses: stackradar/stackradar-action@v1
StackRadar / dependency checkPR #712 adds shell-quote 1.8.3 · CVE-2026-24391CheckingFailed
StackRadar / dependency checkPR #713 bumps it to 1.8.4 · nothing new introducedPassed

Your agent asks. The radar answers.

Connect a coding agent over MCP and it stops guessing what your org runs. You authorize it once from your integration settings, and it reads only what you allow.

coding agent session · StackRadar connected

You, to your agent

Anything urgent in ridgeline/api before I ship?

Agent · asked StackRadar

One thing: semver 7.5.1 is exposed to CVE-2022-25883. The fix is 7.5.2, a patch bump. It comes in through eslint, two paths.

You

Fix it.

Agent

Opening the PR

Starts in observe mode. It merges nothing until a walkthrough hands you the dial.