The Ossprey dashboard is your central hub for monitoring software supply chain security across your repositories. This guide walks you through the key areas of the interface.
Your dashboard home page provides a quick overview of your security status across all monitored projects. At the top, you'll see three key metrics:
- — the total number of projects and repositories you're monitoring (GitHub repos, online scans, CLI scans)
- (Coming Soon) — the total number of software packages (dependencies) analysed across all your assets
- (Coming Soon) — the number of malicious or vulnerable packages found. If this number is greater than zero, investigate immediately.
Below the metrics, an activity chart (coming soon) shows your scanning activity over time, helping you understand how frequently your projects are being scanned and when scans are occurring.
The sidebar provides quick links to Scan Results, GitHub Integrations, and the latest news from the Ossprey blog.
Navigate to from the sidebar to view all your scans. You can filter by:
- — find assets by repository name, organisation, or package name
- — toggle between All and Malicious Only
- — filter by GitHub repositories, online scans, or other scan sources
- — narrow results to a specific time period
Click to clear all filters.
Each asset in the list shows its type, name, last scanned date, and security status:
-
— no security issues detected -
— security issues found that need attention -
— scan currently in progress
Results from multiple scans showing safe and malicious packages
Repositories connected through the GitHub integration are listed on both the Scan Results page and the GitHub Monitoring page. Each shows the repository name, last scan time, and current scan status.
Click any repository to drill into scan details — you'll see the full list of components (dependencies) found, their versions, package types, and vulnerability status. You can filter components by name, package type, or vulnerability status.
Scan results for a package in Ossprey