Release inventory
Keep dependencies and an SBOM for each product release, including releases still running at customer sites.
Track vulnerabilities in shipped environments, from the first SBOM to the next update.
Interactive demo. 3 invaders left. Click, tap, or use Tab and Enter.
Keep dependencies and an SBOM for each product release, including releases still running at customer sites.
Alert the responsible team when a new vulnerability affects a supported release, with available fixes included.
Record application impact, assign an owner, and track the decision to fix, mitigate, or accept a risk.
Draft advisories about affected releases, assign reviewers, track deadlines, and approve communications before publication.
Connect a finding to its assessment, dependency update, and corrected release.
Retrieve past SBOMs, decisions, and advisories when customers or regulators ask about an older release.
Atlas Robotics is a fictional company shipping vision software for inspection robots. This example shows how a real CVE could affect its workflow and a release already running at customer sites.
Security lead
She investigates findings, coordinates disclosure, and keeps customers informed.
Vision engineer
He builds the application, validates fixes, and ships updates.
Stacy and Ryan use prefix.dev’s tools to ship a release and respond when a vulnerability affects it.
Ryan
Vision engineer
Atlas Robotics builds its vision application with Pixi and distributes it through prefix.dev. Release 4.2 includes Pillow 10.2.0, recorded alongside its other dependencies in SBOM revision 7.
Release record
Inspection Robot release 4.2
SBOM revision 7
CycloneDX / SPDX with versions, builds, hashes
A Pillow advisory is published
Pillow 10.2.0 is affected.
Stacy
Security lead
Basilisk identifies a Pillow advisory. An automatic notification tells the vision team that release 4.2 contains the affected version and that Pillow 12.3.0 includes a fix.
New vulnerability for the vision team
Pillow 10.2.0
High (CVSS 4.0: 8.7)
A crafted JPEG2000 image can exhaust memory during decoding.
Stacy
Security lead
Stacy drafts a customer advisory with release 4.2 attached and impact marked “under investigation.” She assigns Ryan as reviewer and checks applicable reporting obligations. A review reminder is scheduled for Ryan.
DISCLOSURE CASE
Unpublished draftReview due today
Reminder scheduled for Ryan
Ryan
Vision engineer
Ryan confirms that uploaded images reach the affected decoder. He updates Pillow, validates the pipeline, and ships 4.2.1 with SBOM revision 8. Stacy adds the fix to the advisory and sends it for approval.
Release 4.2
pillow 10.2.0
CVE-2026-59204
SBOM revision 7
Release 4.2.1
pillow 12.3.0
Resolved in 4.2.1
SBOM revision 8
“Are our robots affected?”
“We’re still running release 4.2.”
Stacy
Security lead
Stacy retrieves the original SBOM, Ryan’s impact assessment, and the reviewed advisory. She can explain the risk and point the customer to 4.2.1. Both supported releases remain monitored, with new findings sent to the vision team.
Inspection Robot release history
Pillow 10.2.0, SBOM revision 7
Affected. Update to 4.2.1
Assessment and advisory retained
Pillow 12.3.0, SBOM revision 8
Resolved in 4.2.1
Validated update recorded
| Capability | Ubuntu + apt | Docker + scanner | Prefix.devSupply Chain SecurityBuilt on RoboStack + Pixi |
|---|---|---|---|
| Environments | |||
| Install ROS packages | Included | Included | Included |
| Isolate application dependencies | ~Requires additional tooling or custom integration | Included | Included |
| Lock resolved application dependencies | ~Requires additional tooling or custom integration | ~Requires additional tooling or custom integration | Included |
| Share locked dependencies across dev and production | ~Requires additional tooling or custom integration | ~Requires additional tooling or custom integration | Included |
| Vulnerability detection | |||
| Generate dependency SBOMs | ~Requires additional tooling or custom integration | Included | Included |
| Scan for known vulnerabilities | ~Requires additional tooling or custom integration | Included | Included |
| Product securityPlanned | |||
| Map findings to supported product releases | ~Requires additional tooling or custom integration | ~Requires additional tooling or custom integration | Planned Supply Chain Security capability |
| Notify the responsible product team | ~Requires additional tooling or custom integration | ~Requires additional tooling or custom integration | Planned Supply Chain Security capability |
| Record impact assessments and fixes | ~Requires additional tooling or custom integration | ~Requires additional tooling or custom integration | Planned Supply Chain Security capability |
| Draft and approve vulnerability disclosures | ~Requires additional tooling or custom integration | ~Requires additional tooling or custom integration | Planned Supply Chain Security capability |
| Keep security history for every release | ~Requires additional tooling or custom integration | ~Requires additional tooling or custom integration | Planned Supply Chain Security capability |
Included~ Requires additional tooling or custom integration
We’re looking for early-access partners with software to maintain over multiple releases.
Let’s talk