Drift Detector

DevSecOps Cockpit {{ counts.reposScanned }} repos · {{ generated }} SBOMSCA VEXSARIF CVE · EOL · sunsets

{{ counts.fixes }} fixes needed · {{ counts.reposAffected }} of {{ counts.reposScanned }} repos affected {{ ownStats.devops }} DevOps · {{ ownStats.developer }} Developer

{{ g.title }}

{{ heroTitle }}

{{ heroWhy }} past-due≤ 6 mo upcoming
{{ tip.vendor }} {{ tip.unit }} retires {{ tip.date }} ({{ tip.when }})
repo {{ tip.repo }}
{{ tip.statusLabel }}
CERTIFIED The tool found and proved these itself. A known rule matched the code, and the retirement date has a cited source. This plane, its tiles and the timeline show only these — the numbers you can trust without a second look. ({{ counts.fixes }})
SHAPED An AI spotted these; the tool re-checked every location. Real call-sites, in code the tool couldn't read on its own — but the rule isn't saved to your catalog yet, so they stay in the AI Frontier plane until you keep them. ({{ shapedCount }})
Vendors this code calls whose retirement list nobody has checked. Zero findings for these is UNAUDITED, not clean.
Sub-dependencies the scan couldn't crawl — private or unreachable.

Nothing found.

View / copy — the canonical drift.json every surface projects from (read-only; the verified source of truth).

{{ driftJsonText }}

No shaping pass has run on this scan. The AI Frontier fills in when an AI shapes a repo the deterministic scan couldn't read — attributing real call-sites the tool then re-checks. Run /drift-absorb on the UNKNOWN repos to shape them, then re-scan and they'll appear here, gate-validated.

{{ sbomHeaderText }}

TypeComponentVersionUsed inVulns
{{ c.type }} {{ c.purl }} {{ c.version }} {{ c.repoCount }} repo{{ c.repoCount === 1 ? '' : 's' }} {{ c.vulnCount }} {{ c.vulnSeverity }}

CycloneDX 1.5 (sbom.json) → Dependency-Track, GitHub · Open in Rancher SBOM viewer ↗

{{ sbomJsonText }}

SPDX 2.3 (sbom.spdx.json) · Open in Rancher SBOM viewer ↗

{{ spdxJsonText }}

{{ sarifHeaderText }}

{{ g.ruleId }}{{ g.count }}
LocationMessageLevel
{{ r.where }} {{ r.message }} {{ r.level }}

SARIF 2.1.0 (drift.sarif.json) — file:line results → GitHub code scanning, VS Code · Open in SARIF web viewer ↗

{{ sarifJsonText }}