Help centre

Security

Vulnerable packages, secrets and the deploy gate

Find known vulnerabilities and leaked credentials in what you deploy, and stop risky deploys.

  1. 1

    Vulnerable packages

    Security reads the composer.lock and package-lock.json of each live website and checks every package against the OSV vulnerability database. Each finding names the version that fixes it. Development-only packages count one level lower.

  2. 2

    Leaked secrets

    On Pro and above, Security looks for keys and tokens (AWS, Stripe, GitHub, Slack, private keys and more) in each website’s code and in recent error reports and logs, and for .env files committed with the code. Secrets are never stored or shown in full.

  3. 3

    Deploy gate

    On the Security overview, choose Block deploys with for an environment. A deploy whose packages have a vulnerability at that level stops before it goes live, and the reason appears on the deploy.

  4. 4

    Accepting a risk

    To let a deploy through anyway, ignore the finding in Security with a reason. The gate treats ignored findings as accepted.

Still stuck? Email us, or send feedback from inside the app.