v2026.05.04.1
Immutable
release. Only release title and notes can be modified.
- Project start. A web application and job queue that clone open-source repositories, run AI-driven security audits inside an isolated container, and record what they find.
- Upload a software bill of materials and Scrutineer queues a scan of every dependency it lists. (#86, @andrew)
- Each confirmed finding gets a drafted security advisory and a candidate patch. (#39 #40, @andrew)
- Individual packages inside a monorepo can be scanned on their own. (#43, @andrew)
- Per-scan cost and token usage is recorded and shown on a usage page. (#79, @andrew)
- Repositories are matched to their CVE Numbering Authority so disclosures are routed to the right contact. (#92, @andrew)