Risk and remediation
Application Security Posture Management
Track security risk, weaknesses and dependencies across commits.
Application Security Posture Management (ASPM) brings Security, ML and SCA results together by commit. It summarizes vulnerabilities, CVEs, CWEs and SBOM data and lets eligible users filter across project commits.
Use the progression views to compare:
- Security risk by commit
- Dependency security risk by commit
- Vulnerability severity by commit
- Weakness metrics by commit
A trend is only comparable when scan scope and engines are compatible. Open the linked source report before using a chart point as release evidence.
Product purpose
Section titled “Product purpose”ASPM provides the project-level view needed to understand how application risk evolves, rather than inspecting every scan in isolation. Supported source, ML and dependency reports contribute to the posture of a selected revision and to progression across commits.
Use it to investigate whether a change introduced new risk, whether dependency exposure changed and which weakness categories need attention. The chart is an entry point into the evidence, not a replacement for the underlying finding.
Interpret progression carefully
Section titled “Interpret progression carefully”A trend can change because code changed, because dependencies changed or because the available scan coverage changed. Compare the revisions and report scope before concluding that risk improved or regressed. Unscanned or stale material does not become current merely because it appears beside newer data.
Use Security Reports for implementation findings, ML Reports for model-based assessment and SCA with SBOM for component evidence. Together these views connect a posture summary to the code and materials that produced it.
The public ASPM release describes security snapshots and commit-based security and dependency progression.

