Supply Chain
Audit NuGet dependencies the way .NET teams actually work: full graph resolution, SBOM export, license controls, typosquat detection, and CI-ready workflows.
Supply chain, runtime testing, and registry controls in one platform. Start with dependency scanning — expand to pentesting and package governance when you need it.
The buying wedge is straightforward: secure NuGet usage first, then layer on runtime testing and stricter package controls.
Audit NuGet dependencies the way .NET teams actually work: full graph resolution, SBOM export, license controls, typosquat detection, and CI-ready workflows.
Run verified scans against the apps and APIs you own. Useful after you have dependency visibility in place.
A controlled NuGet intake layer with provenance, allowlists, and policy enforcement before packages reach production.
A complete security workflow that plugs into the repos and pipelines you already run.
Upload a .csproj, point at a .sln, or trigger via CI. Rorix auto-discovers all project files and resolves the full dependency graph — including transitive packages across target frameworks.
Dependency scanning today. Runtime testing and registry governance when you're ready to expand.
Deep audit with CVSS scores, CWE IDs, fix versions, and remediation guidance powered by OSV, GHSA, NVD, and EPSS exploit prediction.
CycloneDX 1.6 and SPDX 2.3 with full license data included.
Classify licenses as permissive, copyleft, or unknown. Enforce allowlist and blocklist policies.
Levenshtein distance analysis against top NuGet packages to catch malicious name squatting.
Interactive visualization of your full dependency tree with transitive path highlighting.
.csproj, .sln, packages.config, Directory.Packages.props, global.json, nuget.config, .deps.json.
SVG badges for your README showing live security grade and vulnerability count.
Audit on every PR. Auto-comment results, fail on critical vulnerabilities or grade thresholds.
A GitHub App that reviews every PR, and a CLI that runs anywhere. Same findings, same grades, same policies.
Rorix installs as a GitHub App, runs on every PR, and posts a checks summary plus an auto-comment with CVE context, fix paths, and the exact packages that changed.
System.Text.Json 6.0.0 → 8.0.5 resolves CVE-2024-30105The same engine as the GitHub App, available anywhere a shell runs. Ship it in Docker, Jenkins, GitLab, TeamCity, or your own laptop.
Show your security posture with live-updating SVG badges. Drop them into any README, wiki, or dashboard.
<!-- Grade badge -->  <!-- Vuln count badge -->  <!-- SBOM available --> 
No rip-and-replace. Works with the tools you already use.
Built with the guardrails your security and compliance teams require.
SAML 2.0, OIDC, and SCIM user provisioning. Okta, Azure AD, Google Workspace.
Scoped permissions for engineers, security, and leadership. Per-repo and per-team controls.
Pre-built templates for SOC 2 Type II, ISO 27001, FedRAMP, and PCI DSS 4.0. Exportable PDF and CSV evidence.
Every scan, policy change, override, and user action logged with timestamp and actor. SIEM integration via webhooks.
Start with the dependency graph your team already ships. Get vulnerability, SBOM, license, and typosquat coverage without buying a full AppSec platform first.