<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>depproof — Changelog</title>
    <link>https://depproof.com/changelog/</link>
    <atom:link href="https://depproof.com/changelog/rss.xml" rel="self" type="application/rss+xml" />
    <description>Releases and feature updates for the depproof scanner, hub, and firewall.</description>
    <language>en</language>
    <item>
      <title>Scanner: Gate on what is actually being exploited</title>
      <link>https://depproof.com/changelog/#scanner-prioritisation-2026-08</link>
      <guid isPermaLink="false">https://depproof.com/changelog/#scanner-prioritisation-2026-08</guid>
      <pubDate>Mon, 17 Aug 2026 12:00:00 GMT</pubDate>
      <description>A severity threshold alone ships the vulnerability attackers are using: plenty of actively-exploited findings are rated only medium. The CI gate now takes exploitation evidence, CVSS score, and whether a fix exists — and a new fidelity rule fails the build when the dependency graph could not be fully resolved, the one case where a short findings list is the warning rather than the all-clear.</description>
    </item>
    <item>
      <title>Scanner: Go module support</title>
      <link>https://depproof.com/changelog/#scanner-go-2026-07</link>
      <guid isPermaLink="false">https://depproof.com/changelog/#scanner-go-2026-07</guid>
      <pubDate>Thu, 30 Jul 2026 12:00:00 GMT</pubDate>
      <description>The scanner now audits Go projects alongside Java, JavaScript, and Python — the resolved module graph checked against OSV advisories for Go, licenses classified to SPDX, and Go components included in the CycloneDX SBOM and the CI gate. Same self-hosted container; your source never leaves your runner.</description>
    </item>
    <item>
      <title>Hub: The depproof hub — org-wide governance, waivers &amp; audit trail</title>
      <link>https://depproof.com/blog/depproof-hub-release/</link>
      <guid isPermaLink="false">https://depproof.com/changelog/#hub-2026-07</guid>
      <pubDate>Wed, 29 Jul 2026 12:00:00 GMT</pubDate>
      <description>The self-hosted hub aggregates every repo’s scan reports into one cross-repo view — blast-radius search and org-wide license posture — and adds cybersec-owned waivers with an append-only audit trail (posture snapshots, expiry, OpenVEX/CSV export). A centrally-accepted finding stops failing every repo’s CI. Runs in your own network; reports never leave your infrastructure.</description>
    </item>
    <item>
      <title>Scanner: The depproof scanner — self-hosted dependency &amp; license audit</title>
      <link>https://depproof.com/blog/depproof-scanner-release/</link>
      <guid isPermaLink="false">https://depproof.com/changelog/#scanner-2026-07</guid>
      <pubDate>Tue, 28 Jul 2026 12:00:00 GMT</pubDate>
      <description>Audit your dependencies for known vulnerabilities and license risk across Java (Maven, Gradle), JavaScript/Node (npm, pnpm, yarn, bun), and Python (PyPI) — the full transitive tree, a CycloneDX SBOM, and a pass/fail CI gate. Runs self-hosted in GitHub Actions, GitLab CI, or any container; your source never leaves your runner.</description>
    </item>
  </channel>
</rss>