Dependency health Pricing

Choose the coverage your stack needs.

Pricing

Start free. Go deeper when you need to.

Free helps you keep an eye on your dependencies. Pro adds scale and private inventories. Premium is our planned service for proposing code fixes.

For your everyday dependencies

Free

$0 USD · no subscription

Understand your stack and follow the packages that matter.

  • 25 packages in your watchlist
  • Search and assess public packages across 7 ecosystems
  • Public project manifest checks
  • Email alerts and weekly digest
  • Live feed, supply-chain news and repository trendlines
Get started free →
Planned · not available for purchase

Premium

TBA pricing not set

For when a dependency needs a fix and upgrading alone is not enough.

  • Planned: Pro features plus repository-aware AI patch proposals
  • Proposed dependency, configuration or source-code changes
  • Suggested regression tests and a validation report
  • Reviewable patches, with your approval before publication
  • Requires access to the relevant project; usage limits are still being defined
Explore planned Premium →

Pro does not include AI-generated patches. GitHub analysis needs the GitHub App connection to be enabled. Wiz and other vendor imports use supported SBOM exports or CI uploads; native direct connectors currently cover JFrog Artifactory and Xray. Vendor subscriptions are separate.

Compare every feature and limit →

Compare features and limits

A watched package counts once across your projects. Public checks are subject to normal rate limits. Premium entries describe planned scope, not an active entitlement.

FeatureFreeProPremium · planned
Public package search, assessments and project checksIncludedIncludedPlanned: included
Supported package ecosystemsnpm, PyPI, Cargo, Go, Maven, NuGet, RubyGemsAll 7Planned: all 7
Unique watched packages251,000Not set yet
Email alerts and weekly digestIncludedIncludedPlanned: included
Live feed, supply-chain news and trendlinesIncludedIncludedPlanned: included
Slack / Discord and private watchlist feedNot includedIncludedPlanned: included
Private GitHub analysisNot included5 repositories; root package.json + package-lock.json; App setup requiredPlanned: broader project context for patching
Private GitHub analysis allowanceNot included20 analyses per rolling 24 hours; up to 500 direct dependencies per analysisNot set yet
Platform integration sourcesNot included5 sources, separate from GitHub repositoriesPlanned: included; final limits not set
SBOM formatsNot includedCycloneDX JSON 1.4–1.6; SPDX JSON 2.2–2.3Planned: included
Direct vendor connectionsNot includedArtifactory inventory; Xray artifact findings (read-only)Planned: included
Wiz, GitLab, Snyk, Sonatype and other platformsPublic news where availableSupported SBOM exports / CI uploads; no native tenant API connection yetPlanned: included
Integration inventory limitsNot included2,000 components; 2,000 supplied findings; 2 MiB JSON per sourceNot set yet
Integration upload / manual sync allowanceNot included20 actions per rolling 24 hours; hourly scheduled connector refreshesNot set yet
Private data retentionNot applicableGitHub reports: 30 days; integration sources and credentials: expire 30 days after creationNot set yet
Repository-aware AI patch generationNot includedNot includedPlanned; not live

Premium: a proposed fix, with evidence.

Premium is being designed for vulnerable or end-of-life dependencies where there is no straightforward upgrade. With access to the relevant repository, the proposed service would suggest a patch and show what was tested, what passed and what still needs review.

AI patch generation is not currently available in any plan. Premium pricing, usage allowances and launch timing are not set. There is no Premium checkout, and upgrading to Pro does not enable patch generation.

Generated patches would require human review. They would not automatically merge or deploy, or guarantee that a vulnerability is resolved.

What to know before choosing Pro

Private GitHub analysis currently covers root npm manifests and lockfiles, not full project code or every ecosystem. Connection availability is shown before you authorize GitHub.

Integrations import existing inventory and findings; they do not run a new vendor security scan. Xray requires an eligible vendor subscription and a completed scan. Direct JFrog connectors still need validation with your tenant. Provider scan times and successful sync times are shown separately.

You can manage your subscription from your dashboard. Private data stays out of the public crawl queue, and you can delete retained private sources after downgrading.

Open plan and billing settings →