New features, improvements, and fixes to DependencyDesk.
July 21, 2026
Light theme
Redesigned the entire site with a white background for better readability, especially in dependency reports.
Refreshed the getting-started documentation screenshots for the new theme and documented Go and uv support.
July 20, 2026
Scanner and vulnerability reporting upgrades
Added Go support: repositories using Go modules (go.mod) are now fully analyzed.
Expanded Python support with uv.lock parsing, including monorepos with workspace members, alongside the existing pyproject.toml and requirements.txt handling.
Vulnerability scanning now covers every supported ecosystem — not just npm — via integration with the OSV.dev advisory database.
Added a CVSS calculator that computes a severity rating directly from an advisory's CVSS vector when the advisory doesn't declare one, so fewer vulnerabilities show up as "unknown" severity.
Due diligence reports now include a vulnerability summary: a severity breakdown, the repositories affected, the most critical vulnerabilities across the organization, and vulnerability columns in the CSV export.
June 30, 2026
Documentation improvements
Expanded the getting-started guide with a step-by-step walkthrough, including screenshots covering GitHub sign-in, app installation, organization setup, and repository analysis.
June 26, 2026
Vulnerability workflow upgrades
Added a one-click copy button that generates an AI-ready prompt for resolving a flagged dependency vulnerability — paste it into your assistant of choice to get straight to a fix.
Made known vulnerabilities more visible on the organization overview so critical issues are harder to miss.
Made it easier to re-analyze repositories that have already been analyzed.
Streamlined adding more repositories after the initial GitHub App installation.
March 12, 2026
Site updates
Added the SecurityBot.dev badge to the site footer.
March 10, 2026
Blog and resource library launch
Launched the DependencyDesk blog with guides covering software due diligence costs, dependency audits for private equity, seller preparation, and third-party license review for SaaS acquisitions.
Published new resource pages, including What is an SBOM?, What is Technical Due Diligence?, and comparisons of DependencyDesk with Black Duck and other SCA tools.
Improved search and AI discoverability with an expanded sitemap, llms.txt, and structured data across the site.
February 2, 2026
Brand refresh
Updated the homepage hero messaging.
Refreshed the DependencyDesk logo across the site.