Help

What DevRadar does, how to feed it, and where to look when something is missing.

What DevRadar tracks

DevRadar stores an SBOM for each container image you submit and re-scans the stored inventory on a schedule. Because the inventory is kept, it can answer questions a one-shot scanner cannot: which CVEs are new since the last digest, which packages introduced them, and whether a finding is getting older rather than getting fixed.

Getting data in

Submit an SBOM with an API token from API tokens. The submit guide has copy-pasteable commands, and the API reference documents every endpoint.

CycloneDX and SPDX are both accepted. Images are identified by digest, so the same tag pointing at a new digest is tracked as a new image rather than an update in place.

Why a finding changed

Findings move for two reasons: the image changed, or the vulnerability data changed. Trends separates the two. A CVE that appeared without a new digest came from a scanner database update, not from anything you shipped.

Scans run daily. A newly submitted SBOM is scanned on ingest, so you do not have to wait for the next cycle.

Suppressing a finding

Upload a VEX document to record that a finding does not apply to your usage. Suppressed findings stay visible and attributed rather than disappearing — the goal is an auditable record, not a smaller number.

Limits

Per-account limits exist only to keep the shared instance responsive. They are not a paid tier and there is nothing to upgrade to.

Getting in touch

Bugs and feature requests belong in GitHub issues. Security reports have their own process — see SECURITY.md; please do not open a public issue for those.

DevRadar is operated on a best-effort basis: no SLA, no uptime guarantee, and no support commitment. The source is on GitHub under the Apache License 2.0, and you are welcome to run your own instance.