Skip to content

Get started

DevSecOps

Manage application security, software composition, delivery risk and governed operations.

Pervaziv DevSecOps is the project security and delivery console for Pervaziv AI. It brings source analysis, dependency risk, remediation, security posture and configured delivery operations into a connected view of the project.

Sign in, add a project and run a supported scan. Begin with the report for the selected project and revision, then explore the product areas below. The dashboard guide explains navigation and project selection.

Static, deep and ML-assisted analysis provide different views of source risk. Security reports include coverage and findings with severity, confidence, impact and weakness filters. Deep scans support further investigation, while ML reports provide model-based findings with prediction and line-selection filters.

Code-detail and vulnerability views connect results to the relevant source and remediation. Personalized reports let eligible users track their own finding decisions, such as fixed, false-positive or ignored status. Current and stale report indicators help distinguish results for the selected code from older analysis.

Explore scan types, Security Reports, Deep Scan, ML Reports and code details.

Software composition analysis examines project dependencies and the vulnerabilities associated with them. The SCA view includes scan status, dependency and vulnerability summaries, and software bill of materials results. These complement source findings by showing risk introduced through the components the application uses.

SCA and SBOM covers the report and available outputs. Use the dependency version and scanned revision when evaluating a finding.

ASPM brings Security, ML and SCA results together by commit. Progression views show security risk, dependency risk, vulnerability severity and weakness metrics over the project’s history. This helps teams examine how risk changes as the software evolves and identify which report supports a trend.

The posture view supports prioritization across findings and revisions. ASPM and vulnerability reports describe the available views and investigation paths.

Package Analysis supports eligible package files and repository-package sources. Console source selections include Ubuntu, Debian, GNU, RPM, GitHub, GitLab, Bitbucket and Azure Repos. Package reports expose searchable information, scores, scan summaries and finding filters.

The DAST area presents Incident Response Data and Host Scans Data for eligible roles and environments. Those runtime observations complement source and dependency analysis. See Package Analysis and dynamic application security testing for supported scope.

Delivery operations and governed workflows

Section titled “Delivery operations and governed workflows”

The DevOps area provides configured build and deployment paths, provider selection, progress and cancellation controls for eligible projects. Operation availability depends on the project’s connected environment.

Cloud Workflows expose durable task progress, supported approvals and validation or release evidence. Automations schedule eligible work hourly, daily or weekly. Workflow Recipes describe parameterized work with permissions, approval points, budgets and completion checks; supported controls include dry-run preview, run, schedule and version management.

Build and deploy documents delivery operations, and cloud workflows and automations covers the task, schedule and recipe views.

Developer Analytics relates contributor activity to repository security results. Advanced Developer Certification exposes a security score and the supporting metrics, while eligible organization views provide a broader picture of contributor and team activity.

Use these views with their report scope and measurement period. Developer Certification explains the visible scoring and analytics experience.

Area Main output
Source analysis Security, deep-scan and ML findings tied to code
SCA and SBOM Dependency inventory and component vulnerability results
ASPM Risk and weakness progression across commits
Package Analysis Package information, scores and scan reports
DAST Eligible incident-response and host-scan observations
DevOps Configured build and deployment progress
Workflows Task state, approvals, schedules and recipe outcomes
Developer Analytics Contributor security metrics and certification scores

DevSecOps is designed to relate different kinds of evidence rather than treat every report as the same scan. Source findings concern first-party code; SCA concerns third-party and transitive components; package analysis examines eligible packaged artifacts; runtime observations concern executing software. ASPM brings supported reports together across project revisions.

This distinction helps answer practical questions: did the latest commit introduce a weakness, does a dependency carry a known vulnerability, and does the assessed application expose risky behavior? Open the supporting report before interpreting a summary score or progression chart.

Prioritize with severity and exploitation context

Section titled “Prioritize with severity and exploitation context”

Pervaziv’s published security work uses CVSS and EPSS alongside product risk scoring where available. CVSS describes technical severity, while EPSS adds estimated exploitation likelihood. Neither replaces the affected component, exposure, business impact or the evidence behind the finding.

Use the report’s severity, confidence, weakness and impact filters to narrow the review, then investigate the code or package involved. Personalized finding decisions can distinguish fixed, ignored or false-positive results where the report provides those controls. A changed revision needs current assessment; an old score does not establish the security of a new release.

Supply-chain and packaged-software assessment

Section titled “Supply-chain and packaged-software assessment”

The SCA and SBOM offering covers component inventories and dependency relationships, with published support for SPDX and CycloneDX analysis and reports. These artifacts help security teams investigate vulnerable components and help release reviewers understand the software materials in a candidate.

Package Analyzer adds assessment where source is not the starting point. Published releases cover supported Unix packages and eligible Windows binaries, including unpacking and reconstruction for analysis. That does not mean every binary format can be recovered or every vulnerability detected. Use the exact supported input and review the available report coverage.

A useful remediation loop identifies the finding, investigates the relevant code or dependency, prepares a change, validates it and checks the updated revision. The console’s code-detail and AI-assisted report views support investigation; Developer Tools bring implementation closer to the editor. AI Code Review brings pull-request review and repository scanning into GitHub.

Eligible Cloud workflows extend the loop with managed validation and release evidence. Build outcomes, test failures, runtime checks and security observations can be reviewed together for the same candidate. Scheduling or running a workflow is not itself proof that its checks passed.

Developer Analytics combines contributor activity with security information over a selected period. Certification scores can guide a discussion about secure development and training needs. Organization views let authorized admins examine members and aggregate activity without making those views available to every user.

Compare contributors and periods carefully: repository scope, scanned code, activity and available findings all affect the interpretation. A leaderboard is a product metric, not an independent professional qualification.

Roles, subscription entitlements and project permissions determine which areas appear and which operations are available. Roles documents access, and Account & Billing covers shared account and subscription management.

Developer Tools bring investigation and fixes into the editor. AI Code Review exposes the GitHub App and Action integrations. The complete Release Notes archive tracks shipped product changes.