Changelog

New scanners, platform features, and fixes. We ship continuously.

v1.3

  • Pull request scanning: with the GitHub App installed and watch mode on, every PR is scanned automatically — Ship Safe comments the findings in the changed files and sets a shipsafe/security commit status (red on critical/high or an org min-grade violation).
  • OWASP ZAP joins the lineup as the 8th security engine: dynamic (DAST) scanning against your running app or API.
  • Light mode! Switch themes from the sun/moon toggle — with a smooth cross-fade and full support across every page.
  • First-login walkthrough, plan usage meters, and clearer upgrade prompts when you hit a plan limit.
  • Scan results: dismiss findings as false-positive or won’t-fix (the grade recomputes), copy ready-made fix prompts for Claude Code or Cursor, and download SOC 2 evidence packs and executive summaries as PDFs.

v1.2

  • New platform admin console for super admins: cross-tenant overview, organization and user management, and plan overrides.
  • Team collaboration is now self-serve: create a team organization, invite teammates with shareable links, accept invitations, and switch between organizations from the header.
  • Hardened role-based access control on organization settings, members, and governance policies.
  • Clearer scan result states — failed and in-progress scans no longer render as "clean".
  • Polished branding: favicon, app icons, and web manifest.

v1.1

  • Multi-tenant organizations: invite teammates, assign roles (Owner, Admin, Auditor, Developer), and scope repos and scans per organization.
  • Row-level security and per-tenant data isolation in the database.
  • Governance policies: scheduled scans, minimum-grade gates, and Slack notifications.

v1.0

  • Public launch: 7 security engines (Semgrep, AI-pattern rules, Gitleaks, OSV-Scanner, Trivy, hallucinated-package checks, prompt-injection) in one graded report.
  • AI-generated auto-fix pull requests on paid tiers.
  • SOC 2 evidence packs and executive summary PDFs.