Changelog

New features, improvements, and fixes to DependencyDesk.

July 21, 2026

Light theme

  • Redesigned the entire site with a white background for better readability, especially in dependency reports.
  • Refreshed the getting-started documentation screenshots for the new theme and documented Go and uv support.

July 20, 2026

Scanner and vulnerability reporting upgrades

  • Added Go support: repositories using Go modules (go.mod) are now fully analyzed.
  • Expanded Python support with uv.lock parsing, including monorepos with workspace members, alongside the existing pyproject.toml and requirements.txt handling.
  • Vulnerability scanning now covers every supported ecosystem — not just npm — via integration with the OSV.dev advisory database.
  • Added a CVSS calculator that computes a severity rating directly from an advisory's CVSS vector when the advisory doesn't declare one, so fewer vulnerabilities show up as "unknown" severity.
  • Due diligence reports now include a vulnerability summary: a severity breakdown, the repositories affected, the most critical vulnerabilities across the organization, and vulnerability columns in the CSV export.

June 30, 2026

Documentation improvements

  • Expanded the getting-started guide with a step-by-step walkthrough, including screenshots covering GitHub sign-in, app installation, organization setup, and repository analysis.

June 26, 2026

Vulnerability workflow upgrades

  • Added a one-click copy button that generates an AI-ready prompt for resolving a flagged dependency vulnerability — paste it into your assistant of choice to get straight to a fix.
  • Made known vulnerabilities more visible on the organization overview so critical issues are harder to miss.
  • Made it easier to re-analyze repositories that have already been analyzed.
  • Streamlined adding more repositories after the initial GitHub App installation.

March 12, 2026

Site updates

  • Added the SecurityBot.dev badge to the site footer.

March 10, 2026

Blog and resource library launch

  • Launched the DependencyDesk blog with guides covering software due diligence costs, dependency audits for private equity, seller preparation, and third-party license review for SaaS acquisitions.
  • Published new resource pages, including What is an SBOM?, What is Technical Due Diligence?, and comparisons of DependencyDesk with Black Duck and other SCA tools.
  • Improved search and AI discoverability with an expanded sitemap, llms.txt, and structured data across the site.

February 2, 2026

Brand refresh

  • Updated the homepage hero messaging.
  • Refreshed the DependencyDesk logo across the site.