Security that follows your software after release

Track vulnerabilities in shipped environments, from the first SBOM to the next update.

Interactive demo. 3 invaders left. Click, tap, or use Tab and Enter.

Built for the life of your product

Release inventory

Keep dependencies and an SBOM for each product release, including releases still running at customer sites.

Automatic notifications

Alert the responsible team when a new vulnerability affects a supported release, with available fixes included.

Impact assessment

Record application impact, assign an owner, and track the decision to fix, mitigate, or accept a risk.

Vulnerability disclosure

Draft advisories about affected releases, assign reviewers, track deadlines, and approve communications before publication.

Remediation tracking

Connect a finding to its assessment, dependency update, and corrected release.

Release security history

Retrieve past SBOMs, decisions, and advisories when customers or regulators ask about an older release.

Meet Atlas Robotics

Atlas Robotics is a fictional company shipping vision software for inspection robots. This example shows how a real CVE could affect its workflow and a release already running at customer sites.

Meet Stacy

Security lead

She investigates findings, coordinates disclosure, and keeps customers informed.

Meet Ryan

Vision engineer

He builds the application, validates fixes, and ships updates.

Stacy and Ryan use prefix.dev’s tools to ship a release and respond when a vulnerability affects it.

  1. Ryan

    Vision engineer

    Ryan ships Inspection Robot 4.2

    Atlas Robotics builds its vision application with Pixi and distributes it through prefix.dev. Release 4.2 includes Pillow 10.2.0, recorded alongside its other dependencies in SBOM revision 7.

    Release record

    Inspection Robot release 4.2

    pixi.lock (linux-aarch64, vision)

    python3.12.2
    numpy1.26.4
    pillow10.2.0

    SBOM revision 7

    CycloneDX / SPDX with versions, builds, hashes

  2. A Pillow advisory is published

    Pillow 10.2.0 is affected.

    Stacy

    Security lead

    Stacy receives a vulnerability alert

    Basilisk identifies a Pillow advisory. An automatic notification tells the vision team that release 4.2 contains the affected version and that Pillow 12.3.0 includes a fix.

    New vulnerability for the vision team

    Pillow 10.2.0

    High (CVSS 4.0: 8.7)

    CVE-2026-59204

    A crafted JPEG2000 image can exhaust memory during decoding.

    Affects
    Inspection Robot 4.2
    Upstream fix
    Pillow 12.3.0
    Assigned to Stacy
  3. Stacy

    Security lead

    Stacy opens a disclosure case

    Stacy drafts a customer advisory with release 4.2 attached and impact marked “under investigation.” She assigns Ryan as reviewer and checks applicable reporting obligations. A review reminder is scheduled for Ryan.

    DISCLOSURE CASE

    Unpublished draft

    Inspection Robot 4.2

    CVE-2026-59204

    Impact
    Under investigation
    Owner
    Stacy, security lead
    Evidence
    Release 4.2, SBOM revision 7
    Reviewer
    Ryan, vision engineer
    Publication
    Requires approval

    Review due today

    Reminder scheduled for Ryan

  4. Ryan

    Vision engineer

    Ryan validates the fix for the vision pipeline

    Ryan confirms that uploaded images reach the affected decoder. He updates Pillow, validates the pipeline, and ships 4.2.1 with SBOM revision 8. Stacy adds the fix to the advisory and sends it for approval.

    Release 4.2

    pillow 10.2.0

    CVE-2026-59204

    SBOM revision 7

    Release 4.2.1

    pillow 12.3.0

    Resolved in 4.2.1

    SBOM revision 8

  5. “Are our robots affected?”

    “We’re still running release 4.2.”

    Customer

    Stacy

    Security lead

    Stacy answers a customer still running 4.2

    Stacy retrieves the original SBOM, Ryan’s impact assessment, and the reviewed advisory. She can explain the risk and point the customer to 4.2.1. Both supported releases remain monitored, with new findings sent to the vision team.

    Inspection Robot release history

    4.2

    Supported and monitored

    Pillow 10.2.0, SBOM revision 7

    Affected. Update to 4.2.1

    Assessment and advisory retained

    4.2.1

    Supported and monitored

    Pillow 12.3.0, SBOM revision 8

    Resolved in 4.2.1

    Validated update recorded

    The vision team receives new findings for affected releases.

From development environment to supported release

Ubuntu and apt, Docker with a scanner, and Prefix.dev Supply Chain Security
CapabilityUbuntu + aptDocker + scannerPrefix.devSupply Chain SecurityBuilt on RoboStack + Pixi
Environments
Install ROS packagesIncludedIncludedIncluded
Isolate application dependenciesRequires additional tooling or custom integrationIncludedIncluded
Lock resolved application dependenciesRequires additional tooling or custom integrationRequires additional tooling or custom integrationIncluded
Share locked dependencies across dev and productionRequires additional tooling or custom integrationRequires additional tooling or custom integrationIncluded
Vulnerability detection
Generate dependency SBOMsRequires additional tooling or custom integrationIncludedIncluded
Scan for known vulnerabilitiesRequires additional tooling or custom integrationIncludedIncluded
Product securityPlanned
Map findings to supported product releasesRequires additional tooling or custom integrationRequires additional tooling or custom integrationPlanned Supply Chain Security capability
Notify the responsible product teamRequires additional tooling or custom integrationRequires additional tooling or custom integrationPlanned Supply Chain Security capability
Record impact assessments and fixesRequires additional tooling or custom integrationRequires additional tooling or custom integrationPlanned Supply Chain Security capability
Draft and approve vulnerability disclosuresRequires additional tooling or custom integrationRequires additional tooling or custom integrationPlanned Supply Chain Security capability
Keep security history for every releaseRequires additional tooling or custom integrationRequires additional tooling or custom integrationPlanned Supply Chain Security capability

Included~ Requires additional tooling or custom integration

Bring us one product you need to support

We’re looking for early-access partners with software to maintain over multiple releases.

Become a design partnerLet’s talk