Roadmap
현재 상태와 앞으로의 계획. 최근 변경은 changelog 에서.
출시됨 (39)
Core
5-stage AI Repair pipeline
Context → Generate → Sandbox → Rescan → PR. 95% fix rate, ~10s avg.
Core
CycloneDX / SPDX / VEX SBOM export
Core
EU CRA Annex VII PDF report
Core
Auto-patching at scale + policy + CI webhook
org-level policy engine + GitHub webhook trigger
Core
Chaos test harness (Toxiproxy)
Network fault injection for pipeline resilience
Pipeline
Reachability v2 — 25 languages (tree-sitter)
Precise call-site tracking. P=R=F1=1.00 on 97-case real-world benchmark.
Pipeline
Lockfile-only dep-upgrade fast path
Sandbox skip for network-free environments
Pipeline
Exemplar corpus 11,500+ GHSA patches
10k GHSA advisory-database + 1,500 curated
Pipeline
RQ worker — 15 queues
high/default/low + 10 lane-specific + scheduler
Pipeline
C/C++ curated symbol DB (100 libs, 2,498 symbols)
zlib, openssl, libcurl, brotli, libuv, libpq, etc.
Pipeline
R curated symbol DB (55 CRAN, 1,162 symbols)
ggplot2, dplyr, shiny, caret, xgboost, etc.
Pipeline
Vendored C/C++ header dynamic parse
tree-sitter function_declarator extraction from .h files
Lanes
10 Security Lanes
CVE / Container / IaC / Secrets / SAST / Malicious Pkg / LLM Guard / ML-BOM / MCP Audit / Agent Supply Chain
Lanes
LLM Guard — OWASP LLM Top 10 (17 rules)
Lanes
SAST — 3,200+ rules (Semgrep + built-in)
Lanes
Secrets — 1,000+ patterns (built-in + TruffleHog verified)
Lanes
IaC — 1,065+ rules (Trivy/tfsec + built-in)
Lanes
Malicious Package — 5 ecosystems, 41 signals, typosquat
Lanes
ML-BOM (CycloneDX 1.6 mlModelInventory)
HuggingFace pickle scanner included
Security
Row Level Security (PostgreSQL FORCE)
17 tenant tables, SET LOCAL app.current_org_id
Security
Audit log tamper-proof hash chain
SHA256 per-row, /audit-logs/verify
Security
Dependency confusion + typosquat detection
11,899 popular packages corpus across 8 ecosystems
Security
Zero-day Radar (5 sources)
Huntr.dev, GHSA issues, arXiv cs.CR, OSV malicious, OSS-Fuzz
Security
CVE feed sanitization + budget enforcement
backward/non-semver filter + org monthly cost cap
Integrations
GitHub App + installation token flow
Integrations
GitHub Checks API
PR status with confidence score
Integrations
SCIM 2.0 provisioning (Okta / Azure AD)
RFC 7644 compliant
Integrations
OpenTelemetry tracing + metrics
Integrations
Outgoing webhook HMAC-SHA256 signing
SDK
Python SDK — patchguard-ai (PyPI)
pip install patchguard-ai. Sync + Async client.
SDK
CLI — patchops-cli (PyPI)
health, findings, benchmark, scan secrets, scan mlbom
SDK
VS Code extension (skeleton)
Infra
Helm air-gapped chart
Infra
Terraform 3-region active-active
Infra
Public benchmark leaderboard
7 vendors, 46 metrics, 29 features
Product
Changelog + public roadmap pages
Product
Stripe checkout + webhook scaffolding
Product
Continuous Compliance docs (SOC2/FedRAMP/ISO27001 gap)
Product
Red team checklist (20+ RT-* items)
진행 중 (3)
Product
VS Code extension wire-up
Backend 연동 + Marketplace 게시
Product
Website rebuild — 25-language era
Landing / Guide / Roadmap / Quick Check modernization
Pipeline
Sandbox whitelist network mode
Allow egress to registry.npmjs.org, pypi.org only
예정 (12)
Pipeline
SBOM diffing — 'this commit introduced X'
Security
2FA TOTP / WebAuthn
Security
License compliance (GPL/AGPL flagging + policy engine)
Product
Attack Surface Visualizer
Org x dep x vuln graph
Product
Security Posture Score
Org-level KPI dashboard
Product
Threat Model auto-generation (STRIDE)
Product
i18n (EN/KO/JA) + mobile responsive
Integrations
Jira / Linear / ServiceNow sync
Integrations
Slack interactive bot
Core
Multi-region (us-east-1, eu-west-1, ap-northeast-2)
Security
External pentest (Cure53 / Trail of Bits)
Security
SOC 2 Type II auditor kickoff