Know what’s vulnerable before it’s exploited.

Pinhaul watches your Python and Java apps and your Docker containers around the clock — mapping every dependency to live CVE, exploit and EPSS data, and telling you exactly what to patch first.

Free during beta · No credit card · Invite-only onboarding

app.pinhaul.dev/console

My Overview

Projects
3
Open findings
12
Outdated deps
27
Agents online
2

1 known-exploited (KEV) · 2 likely-exploited (EPSS ≥ 0.5)

Run pinhaul findings to see what needs patching first.

  • CVE-2021-44228 · log4j-core 2.14.1

    via botocore → transitive · depth 3

    KEV fix 2.17.1
  • CVE-2024-37891 · urllib3 2.0.7

    python · requests ecosystem

    EPSS 0.94 fix 2.2.2
  • GHSA-9wx4-h78v-vm56 · pillow 10.2.0

    image parsing · container web-frontend

    high fix 10.3.0

Built entirely on free, open security data

Google OSV

CISA KEV

FIRST EPSS

deps.dev

Trivy

endoflife.date

Get started

From zero to full stack visibility in minutes

One command for your runtime, one container for your Docker host. Pinhaul keeps watching after you close the terminal.

Install the SDK

pinhaul init captures your exact runtime inventory — Python and Java, direct and transitive — then streams only names and versions.

pip install pinhaul

Deploy the agent

One docker run and the agent inventories every container on the host, scans images with Trivy, and accepts on-demand scans from the console.

Get the agent image

Fix what matters

Findings are ranked by what’s actually being exploited — CISA KEV first, then EPSS probability — with the exact fixed version for each. No 400-CVE wall of noise.

See the engines

Chat with your stack

Two commands to your first finding

No forms, no scanners to configure, no CI to wire up. If you can install a package, you can know your exposure.

Under a minute.
The SDK fingerprints your runtime in the background and reports before your dev server finishes booting.
Always current.
Snapshots refresh on every deploy and engines re-sweep daily — yesterday’s clean report doesn’t lie to you today.
terminal

$ pip install pinhaul

$ pinhaul init

✓ 214 packages discovered · 61 transitive · python 3.12

✓ snapshot sent · 3 open findings

$ pinhaul findings

KEV CVE-2021-44228 · log4j-core 2.14.1 → 2.17.1

0.94 CVE-2024-37891 · urllib3 2.0.7 → 2.2.2

$ docker run -d -v /var/run/docker.sock:/var/run/docker.sock \

ghcr.io/mkinc42/pinhaul-agent

✓ agent online · 4 containers · image scan queued

Detection engines

Eight engines. Open data. Zero noise.

OSV and Trivy map what’s vulnerable. KEV and EPSS rank what’s being exploited. Freshness, EOL and dependency intelligence watch the rest — and fix-radar catches what no advisory database has yet.

Google OSV

Every advisory, swept daily

free tier
  • CVE-2024-37891 high fix available
  • GHSA-9wx4-h78v-vm56 high fix available
  • CVE-2023-50447 medium no fix yet
  • GHSA-j8xg-fqg3-53r7 low no fix yet
Last sweep: 2h ago · 214 packages checked

CISA KEV

free tier

Known-exploited alerts

In the wild right now

If a dependency of yours lands in the CISA catalog, you know within the day.

The catalog of vulnerabilities with confirmed active exploitation — your queue to the front of the line.

FIRST EPSS

free tier

Exploitation probability

CVE-2024-378910.94
CVE-2023-504470.06

Daily scores from FIRST tell you which of your 400 findings get patched this week — and which can wait.

Fix-radar

Fixed upstream, no CVE yet

premium

radar · strukturag/libheif

1.19.9 — “Fix heap overflow in AVIF decoder” · security-shaped commit, no advisory published

you are pinned to 1.19.8 · upgrade recommended

Fix-radar watches upstream repositories for security fixes that ship before any advisory exists — the window every other scanner misses.

Plus: version freshness (deps.dev) · runtime EOL (endoflife.date) · dependency intelligence · Trivy image scanning on the agent.

Security without the enterprise tax

Everything above runs on data that is free and open. You pay for the watching, not the feeds.

8
detection engines
~60s
to first inventory
2
ecosystems — Python & Java
$0
cost of vulnerability data

Frequently asked questions

No. The SDK sends package names and versions — never your code, secrets, or environment variables. Even your hostname stays home: it’s hashed into a pseudonymous machine id on your machine, and that one-way hash is all we ever see. The agent reads container metadata and image layers on your own host and sends only what it finds: images, packages, vulnerabilities, and redacted log patterns.

Your stack is already running. Start watching it.

One pip install, one docker run, and you’ll know exactly what’s exposed — before someone else finds it for you.