Perpensa user guide
Use these guides to inventory your dependencies, understand findings, and choose a fix you can verify.
Get started
Section titled “Get started”| Your goal | Guide |
|---|---|
| Add a repository and inspect the first scan | Your first scan |
| Understand scores, badges, and their limits | Understand results and scores |
| Go from a finding to a verified fix | Remediate a vulnerability |
A finding is an issue detected in a dependency. An update proposes a version change and may address several findings. A pull request (PR) proposes a repository change. Each has its own state; creating a PR does not confirm a fix.
Find your way around the application
Section titled “Find your way around the application”Open the following pages on your Perpensa instance. Paths shown here belong to the application, not this documentation site.
| Page | Purpose | Available introduction |
|---|---|---|
Overview (/app) |
Organization overview | Your first scan |
Repositories (/app/repos) and repository details |
Repositories, tracked references, and scans | Your first scan |
Inventory (/app/inventory) |
Observed dependencies and versions | Your first scan |
Findings (/app/findings) and finding details |
Vulnerabilities and context | Understand results |
Queue (/app/queue) and update details |
Candidate updates and actions | Remediate a vulnerability |
Pull requests (/app/pull-requests) |
Track proposed changes | Remediate a vulnerability |
Digests (/app/digests) |
Summaries and notification delivery | Detailed reference planned |
Exports (/app/exports) |
Inventory exports, including SBOMs | Detailed reference planned |
Settings (/app/settings) |
Organization, access, policies, and integrations | Detailed reference planned |
Before drawing a conclusion
Section titled “Before drawing a conclusion”Check the active organization, repository, scanned reference, and result date. A queued scan, incomplete inventory, active filter, or suppression may explain an empty list. The absence of findings does not guarantee the absence of vulnerabilities. Your role, plan, and integrations determine which data you can read and which actions you can take.
Scope and versions
Section titled “Scope and versions”This first edition covers the three workflows above. Detailed screen references, instance administration, and advanced features will be added progressively. Documentation is available in English only during this initial phase.
The guides describe behavior checked against commit ecbd364 on September 13,
2026. Your instance may run a different version. Examples named example/* and
their versions are fictional. Application scans use real repository contents and OSV responses. An unavailable
advisory service leaves coverage incomplete; it never supplies example findings.