PATCHTRIAGE
Evidence-informed deployment decisions

Patch what matters first.

Combine global threat evidence with your system exposure, mission impact, and safety context to make one defensible SSVC deployment decision — without letting AI invent a score.

Why this patch first?auditable signal path
01 / FINDScanner evidenceCVE · package · fixed version
02 / THREATExploitation stateActive · Public PoC · None · EPSS watch signal
03 / STAKEHOLDERSSVC factorsExposure · Automatable · Human impact
Upgrade spring-beans on web-frontend
Active · Open · Automatable · High human impact → Immediate
Immediate
CERT/CC SSVC · Deployer model

Severity informs. Your environment decides.

KEV and PoC evidence establish what attackers are doing. SSVC combines that state with how your system is deployed and what failure means to your organization.

SSVC · EExploitationWhat are attackers doing?Active (CISA KEV) · Public PoC · None
SSVC · EXPSystem exposureHow reachable is this system?Open · Controlled · Small
SSVC · AAutomatableCan exploitation be automated?Yes · No · reviewed per vulnerability
SSVC · HIHuman impactWhat happens if exploitation succeeds?Low · Medium · High · Very high, from mission + safety
0
targets in scope
0
known exploited
0
Immediate decisions
decisions verified
inputs from authority

Patch decisions

Decision engine SSVC deterministic
ImmediateAct now · example local SLA 3 days
Out-of-CycleNext opportunity · example SLA 14 days
ScheduledNormal maintenance · example SLA 30 days
DeferMonitor · example review at 90 days
Decision, not detection

See why the same CVE needs a different action here.

Load the bundled evidence. PatchTriage applies the official SSVC Deployer path, shows every inferred input and confidence level, then groups findings into package-level actions.

GLOBAL SIGNALSKEV · EPSS · CVSSwhat attackers can do
VS
SSVC / YOUR SYSTEMImmediatewhat your team should do now

Import a repository

PatchTriage fetches a GitHub SPDX SBOM without cloning or executing repository code. Repository access follows the GitHub credentials configured for this deployment.

Import an organization

Every recently pushed public repository of the account becomes a target with its GitHub Dependency Graph SBOM attached — the same no-clone, no-execution path as a single repository import. Forks and archived repositories are skipped. Each target starts with the official conservative SSVC defaults; review its context before trusting the decision.