Scans your dependencies for known CVEs (Common Vulnerabilities and Exposures) and outdated packages, applies updates, runs your test suite to verify nothing breaks, and opens a PR with the fixes.
Select the repository to scan for CVEs and outdated dependencies.
Run audit and outdated commands for the package manager. List dependencies with known vulnerabilities or major version gaps.
Determine if vulnerable library is used and whether vulnerable functions are called. Show the call chain.
Update the dependency to the fixed version, adjust code if APIs changed, and run tests.
Create a draft pull request with dependency updates and a security analysis report.
Start building with a free Ona account.
This website uses cookies to enhance the user experience. Read our cookie policy for more info.