vciy
How a stack watch works

Name what you run. Hear when a CVE touches it.

A stack is a watchlist: the products you run, named once, so you hear when a CVE touches one of them. This page says what fires an alert, what does not, and where it goes.

What fires an alert

These changes count, each tied to a product in your stack.

Everything else is routine. A source republishing a value it already holds is not a change at all. Routine changes are listed in a weekly digest and never alert on their own.

A probability that lands less than 5 points past a line waits. It becomes an alert if it moves 5 points past the line, or if it is still across the line at the next daily load.

Your version changes the alert

When you give a version, we place it against the ranges the CVE record publishes for that product.

An alert is lowered, never dropped. The change stays listed. Only an exact not-affected answer lowers anything, because unknown beats a false clear.

Where it goes

Alerts that count are sent when the checker finds them. Record changes are digested daily. Routine changes are digested weekly, on the weekday you choose.

PlanStacksProducts per stackSeatsAlerts go to
Community151Email
Practitioner3Unlimited3Email and Slack
Advisor10Unlimited3Email and Slack
CustodyUnlimitedUnlimited10Email and Slack

These are the plan allowances on the pricing page. Compare plans

The weekly all-clear

The week nothing moves, a single line says so: nothing moved on what you watch this week. It goes by email, on your digest day, and only when no material or record change was found.

It is sent only when our checker's own receipt proves it read every public change for the whole week. When we cannot prove that, we send nothing. A missing all-clear means a gap on our side, never safety.

The proof link

Each alert carries a proof link. A colleague opens it without an account. It shows the public CVE facts and the product you watch, and it writes nothing.