Know what’s vulnerable before it’s exploited.
Pinhaul watches your Python and Java apps and your Docker containers around the clock — mapping every dependency to live CVE, exploit and EPSS data, and telling you exactly what to patch first.
Free during beta · No credit card · Invite-only onboarding
My Overview
Projects
Findings
Alerts
My Overview
- Projects
- 3
- Open findings
- 12
- Outdated deps
- 27
- Agents online
- 2
1 known-exploited (KEV) · 2 likely-exploited (EPSS ≥ 0.5)
Run pinhaul findings to see what needs patching first.
-
CVE-2021-44228 · log4j-core 2.14.1
via botocore → transitive · depth 3
KEV fix 2.17.1 -
CVE-2024-37891 · urllib3 2.0.7
python · requests ecosystem
EPSS 0.94 fix 2.2.2 -
GHSA-9wx4-h78v-vm56 · pillow 10.2.0
image parsing · container web-frontend
high fix 10.3.0
Built entirely on free, open security data
Google OSV
CISA KEV
FIRST EPSS
deps.dev
Trivy
endoflife.date
Get started
From zero to full stack visibility in minutes
One command for your runtime, one container for your Docker host. Pinhaul keeps watching after you close the terminal.
- Install the SDK
-
pinhaul initcaptures your exact runtime inventory — Python and Java, direct and transitive — then streams only names and versions. - Deploy the agent
-
One
docker runand the agent inventories every container on the host, scans images with Trivy, and accepts on-demand scans from the console. - Fix what matters
-
Findings are ranked by what’s actually being exploited — CISA KEV first, then EPSS probability — with the exact fixed version for each. No 400-CVE wall of noise.
Chat with your stack
Two commands to your first finding
No forms, no scanners to configure, no CI to wire up. If you can install a package, you can know your exposure.
- Under a minute.
- The SDK fingerprints your runtime in the background and reports before your dev server finishes booting.
- Always current.
- Snapshots refresh on every deploy and engines re-sweep daily — yesterday’s clean report doesn’t lie to you today.
$ pip install pinhaul
$ pinhaul init
✓ 214 packages discovered · 61 transitive · python 3.12
✓ snapshot sent · 3 open findings
$ pinhaul findings
KEV CVE-2021-44228 · log4j-core 2.14.1 → 2.17.1
0.94 CVE-2024-37891 · urllib3 2.0.7 → 2.2.2
$ docker run -d -v /var/run/docker.sock:/var/run/docker.sock \
ghcr.io/mkinc42/pinhaul-agent
✓ agent online · 4 containers · image scan queued
Detection engines
Eight engines. Open data. Zero noise.
OSV and Trivy map what’s vulnerable. KEV and EPSS rank what’s being exploited. Freshness, EOL and dependency intelligence watch the rest — and fix-radar catches what no advisory database has yet.
Google OSV
Every advisory, swept daily
- CVE-2024-37891 high fix available
- GHSA-9wx4-h78v-vm56 high fix available
- CVE-2023-50447 medium no fix yet
- GHSA-j8xg-fqg3-53r7 low no fix yet
CISA KEV
free tierKnown-exploited alerts
In the wild right now
If a dependency of yours lands in the CISA catalog, you know within the day.
The catalog of vulnerabilities with confirmed active exploitation — your queue to the front of the line.
FIRST EPSS
free tierExploitation probability
Daily scores from FIRST tell you which of your 400 findings get patched this week — and which can wait.
Fix-radar
Fixed upstream, no CVE yet
radar · strukturag/libheif
1.19.9 — “Fix heap overflow in AVIF decoder” · security-shaped commit, no advisory published
you are pinned to 1.19.8 · upgrade recommended
Fix-radar watches upstream repositories for security fixes that ship before any advisory exists — the window every other scanner misses.
Plus: version freshness (deps.dev) · runtime EOL (endoflife.date) · dependency intelligence · Trivy image scanning on the agent.
Security without the enterprise tax
Everything above runs on data that is free and open. You pay for the watching, not the feeds.
- 8
- detection engines
- ~60s
- to first inventory
- 2
- ecosystems — Python & Java
- $0
- cost of vulnerability data
Frequently asked questions
-
No. The SDK sends package names and versions — never your code, secrets, or environment variables. Even your hostname stays home: it’s hashed into a pseudonymous machine id on your machine, and that one-way hash is all we ever see. The agent reads container metadata and image layers on your own host and sends only what it finds: images, packages, vulnerabilities, and redacted log patterns.
-
Snapshots fingerprint your inventory and skip anything that hasn’t changed — client-side and again server-side. Most runs never leave your machine, and the ones that do are a small JSON payload.
-
Google OSV for advisories, CISA’s KEV catalog for active exploitation, FIRST’s EPSS for probability, deps.dev for version freshness, endoflife.date for runtime EOL, and Aqua’s Trivy for container images. All free and open — refreshed daily.
-
Most supply-chain attacks are fixed upstream days or weeks before an advisory is published. Fix-radar watches the repositories behind your pinned dependencies for security-shaped commits and flags them — with the fix version — even when no CVE exists yet.
-
During the beta, everything is free for waitlist members — including premium engines like fix-radar. When we introduce tiers, the core engines stay free and beta builders keep what they joined with. Join the waitlist to get your invite.
-
The SDK and agent are open source (MIT) and live on GitHub. Point them at the Pinhaul cloud, or run the whole stack yourself from source.
Your stack is already running. Start watching it.
One pip install, one docker run, and you’ll know exactly what’s exposed — before someone else finds it for you.