Docs

Dependency monitoring,
without the fog.

A practical guide for teams connecting repos, routing alerts, and keeping package risk visible without turning every update into a manual investigation.

What You Get

SupplyGuard gives engineering teams one place to see which repos carry dependency risk and which issues need attention first.

It is designed for practical monitoring: less digging, less guesswork, and fewer surprises when a bad package version lands.

  • Repo-level dependency visibility
  • Alert routing that stays tied to the right org and channel
  • Fresh checks when new advisories appear
  • A clean view of direct and transitive package exposure
How Teams Use It

Connect GitHub, choose the repos you want covered, add Slack, and let the dashboard do the heavy lifting.

From there, teams can review current exposure, spot suspicious packages, and act before a dependency issue spreads.

  • Connect GitHub
  • Pick the repos to monitor
  • Add a Slack destination
  • Review current package risk
  • Respond faster when alerts land
Why It Stays Useful

Dependency problems are easy to miss when they are scattered across repos, teams, and stale versions that still ship.

SupplyGuard keeps that exposure visible so teams do not have to rediscover the same risk by hand every time the ecosystem changes.

  • Less manual checking
  • Less waiting for someone else to notice
  • Less ambiguity about ownership
  • More confidence in what needs action now
What You Can See

The dashboard brings repo coverage, package counts, direct dependencies, transitive dependencies, and active findings into one working view.

That makes it easier to answer the questions teams actually ask: what changed, what is exposed, and what should move first.

  • Repo-by-repo package visibility
  • Direct versus transitive split
  • Open critical, high, and suspicious issues
  • Recent scans and active findings
Designed For Real Teams

This is built for teams that need enough signal to act, not another wall of security jargon to decode.

The product keeps the experience simple: connect, review, route, respond.

  • Simple setup
  • Clear ownership
  • Readable repo health
  • Faster triage
Boundaries

SupplyGuard helps teams spot dependency risk and respond faster. It does not replace broader security review across your stack.

Use it to keep package exposure visible, organized, and assigned to the right people.

  • Dependency monitoring
  • Clear ownership
  • Faster response
  • No promise of perfect coverage