acme/platform-api
fix/cve-2026-2178
ready 6m
Pin pgwire to 0.14.4 to address GHSA-2026-2178
Bumps pgwire from 0.14.2 to 0.14.4 · sandbox run #412
trigger:GHSA-2026-2178Get started
Three steps close the gap between joining the waitlist and a Driftlock deployment in your VPC. You bring two watchlist surfaces and a CI identity; Driftlock brings the hermetic sandbox and the audit trail — your reviewers see only the pull requests that traced back to a real signal.
connect repo → configure → morning PR
The three steps
Each step has a single team owner. Most trials reach the morning-digest PR within five working days; air-gapped deployments take a few days longer at step two for offline runner signing.
Step 1
Install the Driftlock GitHub App on the repos you want watched. Webhook subscriptions for pushes, pull requests, branch updates, Dependabot alerts, and check runs start landing in the in-VPC watcher within minutes — no new credentials required.
Step 2
Choose the signal sources the watcher should listen on — Dependabot, CI failures, NVD high-severity CVEs, on-call alerts — and the approver group whose sign-off closes a PR. A committed .driftlock/config.yaml pins both, reviewed by your platform team before anything drafts.
.driftlock/config.yaml
committed with the repo
# .driftlock/config.yaml
# committed alongside your repo; the watcher reads it on each branch draft.
sources:
- github.dependabot # Dependabot alerts as a branch trigger
- ci.github-actions # failed CI jobs surface as branch triggers
- nvd.high # NVD high+CVSS as branch triggers
- oncall.pagerduty # paged alerts as branch triggers
approvers:
- "@acme/platform-eng" # review queue; SIGNED-OFF closes the PR
sandbox:
toolchain: hermetic-nix
cache: shared-topology
egress: deny-by-default
signing:
commit: kms://acme/cosign
sbom: kms://acme/sbom
rekor: https://rekor.acme.internalStep 3
By the next morning, an audit-linked pull request sits on your desk — every row links back to the alert, log line, or CVE GUID that produced it. Reviewers sign off in /demo without retracing the trigger; the diff stays within the path that tripped.
acme/platform-api
fix/cve-2026-2178
ready 6m
Bumps pgwire from 0.14.2 to 0.14.4 · sandbox run #412
trigger:GHSA-2026-2178acme/payments
fix/flaky-test-charge-retry
ready 12m
No dep change · sandbox run #413
trigger:CI run #8421acme/auth-bff
chore/bump-jose-5.9
ready 18m
Bumps jose from 5.7.0 to 5.9.6 · sandbox run #414
trigger:NVD CVE-2026-0917Reviewers sign off in /demo — the live queue with the same rows but interactive toggles.
See the live sign-off flowconnect repo → configure → first PR
What lands on your desk
The trial is scoped, not a sandbox demo. Driftlock deploys into your cloud account, runs against a CI identity you already trust, and finishes with a walkthrough of the resulting audit trail. Every PR carries the alert, log, or advisory that produced it — the same flow /demo exercises, run against a live repo.
Nothing is shared with us after the trial ends unless you opt in. The deployment goes with you — same keys, same VPC, same audit log.
Trial deliverables
ten days · self-hosted · audit-linked
Reserve a trial slot
Drop your work email below and we'll reach out within two business days to scope a trial against one of your real monorepos. Each cohort runs the four deliverables above; pricing matches the tier the trial validates.
Start with the waitlist
We'll reply with a calendar link and a one-page brief on the trial. No follow-up sequence — just the call.