Software delivery
Package Analysis
Assess supported package formats and review package scan reports.
Package Analysis accepts eligible package files and repository-package sources, then exposes searchable package information, scores and scan reports. Supported package-source types in the console are:
- Ubuntu
- Debian
- GNU
- RPM
- GitHub
- GitLab
- Bitbucket
- Azure Repos
Package Scan Reports summarize files, rules, vulnerabilities and elapsed time and provide report filters. The feature is subscription-gated. Analyze only trusted package inputs and confirm the exact version before acting on a score.
Assessment when source is not the starting point
Section titled “Assessment when source is not the starting point”Package Analyzer supports investigating eligible distributed packages and embedded binaries. Published releases describe unpacking and reconstruction for analysis of supported Unix packages and Windows binaries. This extends security investigation beyond a repository’s original source files.
The input must still be supported by the enabled console path. The package source selector above is not a promise that every binary format or archive can be reconstructed. Check the result’s coverage and limitations before using it to make a distribution decision.
Reports and prioritization
Section titled “Reports and prioritization”Searchable package information and AI Risk Score help locate candidates for review. Open the associated scan report for file, rule, vulnerability and timing details, then use the report filters to investigate relevant findings. Published product work also describes CVSS and EPSS as inputs to prioritization where available.
A summary score is not a substitute for understanding the affected package, its version and use in your environment. Compare like inputs and retain the artifact identity when the report is used as evidence.
How it complements other scans
Section titled “How it complements other scans”Source scans examine the project implementation. SCA inventories dependencies. Package Analysis examines eligible packaged software. Use the output suited to the material you have, and obtain fresh evidence after an artifact changes.
See the Package Analyzer introduction and Windows binary analysis release.

