Skip to content

Perpensa user guide

Use these guides to inventory your dependencies, understand findings, and choose a fix you can verify.

Your goal Guide
Add a repository and inspect the first scan Your first scan
Understand scores, badges, and their limits Understand results and scores
Go from a finding to a verified fix Remediate a vulnerability

A finding is an issue detected in a dependency. An update proposes a version change and may address several findings. A pull request (PR) proposes a repository change. Each has its own state; creating a PR does not confirm a fix.

Open the following pages on your Perpensa instance. Paths shown here belong to the application, not this documentation site.

Page Purpose Available introduction
Overview (/app) Organization overview Your first scan
Repositories (/app/repos) and repository details Repositories, tracked references, and scans Your first scan
Inventory (/app/inventory) Observed dependencies and versions Your first scan
Findings (/app/findings) and finding details Vulnerabilities and context Understand results
Queue (/app/queue) and update details Candidate updates and actions Remediate a vulnerability
Pull requests (/app/pull-requests) Track proposed changes Remediate a vulnerability
Digests (/app/digests) Summaries and notification delivery Detailed reference planned
Exports (/app/exports) Inventory exports, including SBOMs Detailed reference planned
Settings (/app/settings) Organization, access, policies, and integrations Detailed reference planned

Check the active organization, repository, scanned reference, and result date. A queued scan, incomplete inventory, active filter, or suppression may explain an empty list. The absence of findings does not guarantee the absence of vulnerabilities. Your role, plan, and integrations determine which data you can read and which actions you can take.

This first edition covers the three workflows above. Detailed screen references, instance administration, and advanced features will be added progressively. Documentation is available in English only during this initial phase.

The guides describe behavior checked against commit ecbd364 on September 13, 2026. Your instance may run a different version. Examples named example/* and their versions are fictional. Application scans use real repository contents and OSV responses. An unavailable advisory service leaves coverage incomplete; it never supplies example findings.