Skip to content

[K9CODESEC-1666] Document lockfile-less SCA scanning #37555

Draft
rjcoulter22 wants to merge 3 commits into
masterfrom
ryan.coulter/k9vuln-14436-docs
Draft

[K9CODESEC-1666] Document lockfile-less SCA scanning #37555
rjcoulter22 wants to merge 3 commits into
masterfrom
ryan.coulter/k9vuln-14436-docs

Conversation

@rjcoulter22

@rjcoulter22 rjcoulter22 commented Jun 16, 2026

Copy link
Copy Markdown
Contributor

What does this PR do? What is the motivation?

In the SCA product we now support scanning manifest files for certain environments when no lockfiles are present. As part of this we will also resolve version ranges from these files ourself into concrete versions for a library - see this confluence page .

This adds a Lockfile-less scanning section to the static SCA setup page so customers know package.json and pyproject.toml are now scanned when no lockfile is present, including a section on how we resolve version ranges from those files. Note we will have a phased roll out of this feature to be able to monitor side effects, and this will be merged when the necessary feature flags are fully enabled for all customers.

Merge instructions

Merge readiness:

  • Ready for merge

AI assistance

AI-assisted draft, manually reviewed and edited.

@rjcoulter22 rjcoulter22 force-pushed the ryan.coulter/k9vuln-14436-docs branch from e9bc7e5 to d3b7862 Compare June 16, 2026 15:04
@github-actions

Copy link
Copy Markdown
Contributor

Preview links (active after the build_preview check completes)

Modified Files

@rjcoulter22 rjcoulter22 changed the title Document lockfile-less SCA scanning for package.json and pyproject.toml [K9CODESEC-1666] Document lockfile-less SCA scanning Jun 16, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant