✦ AI-powered DevSecOps & remediation

Detect your CVEs. Fix them automatically.

Wadjet connects your GitHub and GitLab repositories, scans your dependencies and images, then opens ready-to-merge pull requests that fix vulnerabilities before they get exploited.

See the dashboard preview
GitHub·GitLab·Google
No agent to install · revoke access anytime
Security postureSample data

Dashboard & overview

Continuous vulnerability indexing across your scanned repositories and images.

Risk overview
224

Critical & high findings

Across 16 scanned images · triage first

31 critical· 193 high
Severity breakdown484 total
Critical
31 6.4%
High
193 39.9%
Medium
226 46.7%
Low
34 7.0%

Vulnerabilities

484

Across 16 scanned repository images

Scanned images

16

Continuous monitoring

Last scan

09/22/2026

Triggered by CI/CD

Fleet risk

Scanned images

Sample data
Image / repoLast scanFindingsStatus
acme/payments-api
C17H63M75L15
09/22/2026
170
Action needed
acme/auth-service
C2H29M43L7
09/22/2026
81
Action needed
acme/web-frontend
C4H29M24L5
09/21/2026
62
Action needed
acme/batch-jobs
No open findings
09/01/2026
0
Clean
acme/docs-site
No open findings
08/30/2026
0
Clean
How it works
  1. 1.Connect a repository

    GitHub, GitLab or Google — read-only access.

  2. 2.Scan

    Dependencies and images analysed, CVEs correlated.

  3. 3.Fix

    An upgrade PR ready to review and merge.

Recent activity

Scan completed on payments-api — 170 vulnerabilities

09/22/2026 21:10

Remediation PR opened for auth-service

09/21/2026 19:44

Image batch-jobs marked clean

09/01/2026 14:12
CVE inspector & automatic fixes

Remediation workflow

Wadjet finds the fixed version and opens the upgrade pull request for you.

Maven & npm
CVE-2021-44228Critical 10.0Exploited in the wildLog4Shell

Remote code execution via JNDI lookups: an attacker who can control a logged message can load and execute arbitrary code from a remote LDAP server.

AFFECTED PACKAGE
org.apache.logging.log4j:log4j-core
2.14.1→2.17.1 (fixed)
TARGET REPOSITORY
acme/payments-api
Maven project · pom.xml
ECOSYSTEM
maven
Direct version bump, no API break
pom.xml
Diff preview
  <dependency>
    <groupId>org.apache.logging.log4j</groupId>
    <artifactId>log4j-core</artifactId>
-   <version>2.14.1</version>+   <version>2.17.1</version>  </dependency>
Findings pending remediationSample data
CVE-2022-42889 CRITICAL 9.8—org.apache.commons:commons-text 1.9 → 1.10.0
CVE-2023-44487 HIGH 7.5—io.netty:netty-codec-http2 4.1.97.Final → 4.1.100.Final
CVE-2024-4068 HIGH 7.5—braces 3.0.2 → 3.0.3
CVE-2024-4067 MEDIUM 5.3—micromatch 4.0.5 → 4.0.8
Features

Everything you need to secure your projects

One developer-first platform, from detection to fix.

Automatic remediation

Wadjet opens a pull request that bumps the dependency to the version fixing the CVE — for Maven and npm alike.

CVE Explorer

Browse and filter thousands of CVEs by severity, date, package and ecosystem.

Built-in AI chat

Ask natural-language questions about your vulnerabilities and get analyses and fix plans.

Repository & image scanning

Connect your GitHub or GitLab repositories to scan dependencies and images automatically.

SBOM & reports

Generate Software Bills of Materials and export complete reports for your teams.

Continuous scanning

Schedule recurring scans and track how your exposure evolves over time.

Frequently asked questions

Questions you are probably asking

How does Wadjet fix CVEs automatically?

Wadjet detects the vulnerability, identifies the package version that fixes it, then opens a ready-to-review pull request on your repository. Nothing is merged automatically: review and merge stay under your control.

Which ecosystems are supported for automatic remediation?

npm and Maven today. Other ecosystems (OS packages, Go, Python…) are detected and listed in the CVE Explorer, but not fixed automatically yet.

Which repositories can I connect?

Your GitHub and GitLab repositories, through a secure OAuth connection.

Is remediation triggered automatically, or do I approve it?

You trigger it yourself, one CVE at a time or in one click for every fixable CVE in the filtered list. Wadjet then opens the pull request; merging stays under your control.

What is an SBOM and what is it used for in Wadjet?

An SBOM (Software Bill of Materials) lists every dependency of a project. Wadjet generates it to give you full visibility into what your repositories and images are made of.

Get started in 60 seconds

Sign in with your account and run your first scan. Your first remediation PR can be ready today.

Secure sign-in via OAuth 2.0 · Revoke access anytime from your settings