Detect your CVEs.
Fix them automatically.
Wadjet connects your GitHub and GitLab repositories, scans your dependencies and images, then opens ready-to-merge pull requests that fix vulnerabilities before they get exploited.
Dashboard & overview
Continuous vulnerability indexing across your scanned repositories and images.
Critical & high findings
Across 16 scanned images · triage first
Vulnerabilities
484
Across 16 scanned repository images
Scanned images
16
Continuous monitoring
Last scan
09/22/2026
Triggered by CI/CD
Scanned images
| Image / repo | Last scan | Findings | Status |
|---|---|---|---|
acme/payments-api C17H63M75L15 | 09/22/2026 | 170 | Action needed |
acme/auth-service C2H29M43L7 | 09/22/2026 | 81 | Action needed |
acme/web-frontend C4H29M24L5 | 09/21/2026 | 62 | Action needed |
acme/batch-jobs No open findings | 09/01/2026 | 0 | Clean |
acme/docs-site No open findings | 08/30/2026 | 0 | Clean |
1.Connect a repository
GitHub, GitLab or Google — read-only access.
2.Scan
Dependencies and images analysed, CVEs correlated.
3.Fix
An upgrade PR ready to review and merge.
Scan completed on payments-api — 170 vulnerabilities
09/22/2026 21:10Remediation PR opened for auth-service
09/21/2026 19:44Image batch-jobs marked clean
09/01/2026 14:12Remediation workflow
Wadjet finds the fixed version and opens the upgrade pull request for you.
Remote code execution via JNDI lookups: an attacker who can control a logged message can load and execute arbitrary code from a remote LDAP server.
<dependency> <groupId>org.apache.logging.log4j</groupId> <artifactId>log4j-core</artifactId> - <version>2.14.1</version>+ <version>2.17.1</version> </dependency>
Everything you need to secure your projects
One developer-first platform, from detection to fix.
Automatic remediation
Wadjet opens a pull request that bumps the dependency to the version fixing the CVE — for Maven and npm alike.
CVE Explorer
Browse and filter thousands of CVEs by severity, date, package and ecosystem.
Built-in AI chat
Ask natural-language questions about your vulnerabilities and get analyses and fix plans.
Repository & image scanning
Connect your GitHub or GitLab repositories to scan dependencies and images automatically.
SBOM & reports
Generate Software Bills of Materials and export complete reports for your teams.
Continuous scanning
Schedule recurring scans and track how your exposure evolves over time.
Questions you are probably asking
How does Wadjet fix CVEs automatically?
Wadjet detects the vulnerability, identifies the package version that fixes it, then opens a ready-to-review pull request on your repository. Nothing is merged automatically: review and merge stay under your control.
Which ecosystems are supported for automatic remediation?
npm and Maven today. Other ecosystems (OS packages, Go, Python…) are detected and listed in the CVE Explorer, but not fixed automatically yet.
Which repositories can I connect?
Your GitHub and GitLab repositories, through a secure OAuth connection.
Is remediation triggered automatically, or do I approve it?
You trigger it yourself, one CVE at a time or in one click for every fixable CVE in the filtered list. Wadjet then opens the pull request; merging stays under your control.
What is an SBOM and what is it used for in Wadjet?
An SBOM (Software Bill of Materials) lists every dependency of a project. Wadjet generates it to give you full visibility into what your repositories and images are made of.
Get started in 60 seconds
Sign in with your account and run your first scan. Your first remediation PR can be ready today.
Secure sign-in via OAuth 2.0 · Revoke access anytime from your settings