History
Every completed assessment for this application, what each one concluded, and what changed between any two of them. Both sides of a comparison are frozen records, so the catalog growing since cannot move either number.
Completed runs
| Completed | Kind | Coverage | Moved | Recorded | Compare |
|---|---|---|---|---|---|
| September 8, 2026 | Review | 47% | +4.4 points | 250 scopes recorded | as earlieras later |
| June 9, 2026 | Self-assessment | 43% | 244 scopes recorded | as earlieras later |
The worked example carries two runs: an initial self-assessment and a review three months later, after container image scanning and automated dependency updates were introduced and the pull-request gate was made blocking.
Comparing Jun 9, 2026 with Sep 8, 2026
43% → 47%
36 scopes changed in your setup, and the profile changed what it asks for in 6 scopes.
6 scopes became required. A coverage figure that moved for that reason moved because the profile changed, not because the work did.
What changed in your setup
Things you control: a scope something now covers, something that stopped covering one, a control that enforces harder or softer, a process that matured.
| What happened | Control | Where | Before → after | Weight |
|---|---|---|---|---|
| gained | Container Image Vulnerability Scan | Development · Docker · Build · CI Pipeline | nothing → Trivy image scan in CI and registry | 2 |
| gained | Container Image Vulnerability Scan | Development · Docker · Build · Registry | nothing → Trivy image scan in CI and registry | 2 |
| gained | Container Image Vulnerability Scan | Test · Docker · Build · CI Pipeline | nothing → Trivy image scan in CI and registry | 2 |
| gained | Container Image Vulnerability Scan | Test · Docker · Build · Registry | nothing → Trivy image scan in CI and registry | 2 |
| gained | Container Image Vulnerability Scan | Production · Docker · Build · CI Pipeline | nothing → Trivy image scan in CI and registry | 2 |
| gained | Container Image Vulnerability Scan | Production · Docker · Build · Registry | nothing → Trivy image scan in CI and registry | 2 |
| gained | Automated Dependency Updates | Development · Java · Code · Pull Request | nothing → Renovate dependency update pull requests | 1 |
| gained | Automated Dependency Updates | Development · Spring Boot · Code · Pull Request | nothing → Renovate dependency update pull requests | 1 |
| gained | Automated Dependency Updates | Development · React · Code · Pull Request | nothing → Renovate dependency update pull requests | 1 |
| gained | Automated Dependency Updates | Test · Java · Code · Pull Request | nothing → Renovate dependency update pull requests | 1 |
| gained | Automated Dependency Updates | Test · Spring Boot · Code · Pull Request | nothing → Renovate dependency update pull requests | 1 |
| gained | Automated Dependency Updates | Test · React · Code · Pull Request | nothing → Renovate dependency update pull requests | 1 |
| gained | Automated Dependency Updates | Production · Java · Code · Pull Request | nothing → Renovate dependency update pull requests | 1 |
| gained | Automated Dependency Updates | Production · Spring Boot · Code · Pull Request | nothing → Renovate dependency update pull requests | 1 |
| gained | Automated Dependency Updates | Production · React · Code · Pull Request | nothing → Renovate dependency update pull requests | 1 |
| stronger | SAST Pull Request Gate | Java · Code · Pull Request | a warning → blocking | 3 |
| stronger | SAST Pull Request Gate | Spring Boot · Code · Pull Request | a warning → blocking | 3 |
| stronger | SAST Pull Request Gate | React · Code · Pull Request | a warning → blocking | 3 |
| more mature | Dependency Composition Scan | Development · Java · Code · Pull Request | Available → Automated | 2 |
| more mature | Dependency Composition Scan | Development · Java · Build · CI Pipeline | Available → Automated | 2 |
| more mature | Dependency Composition Scan | Development · Spring Boot · Code · Pull Request | Available → Automated | 2 |
| more mature | Dependency Composition Scan | Development · Spring Boot · Build · CI Pipeline | Available → Automated | 2 |
| more mature | Dependency Composition Scan | Development · React · Code · Pull Request | Available → Automated | 2 |
| more mature | Dependency Composition Scan | Development · React · Build · CI Pipeline | Available → Automated | 2 |
| more mature | Dependency Composition Scan | Test · Java · Code · Pull Request | Available → Automated | 2 |
| more mature | Dependency Composition Scan | Test · Java · Build · CI Pipeline | Available → Automated | 2 |
| more mature | Dependency Composition Scan | Test · Spring Boot · Code · Pull Request | Available → Automated | 2 |
| more mature | Dependency Composition Scan | Test · Spring Boot · Build · CI Pipeline | Available → Automated | 2 |
| more mature | Dependency Composition Scan | Test · React · Code · Pull Request | Available → Automated | 2 |
| more mature | Dependency Composition Scan | Test · React · Build · CI Pipeline | Available → Automated | 2 |
| more mature | Dependency Composition Scan | Production · Java · Code · Pull Request | Available → Automated | 2 |
| more mature | Dependency Composition Scan | Production · Java · Build · CI Pipeline | Available → Automated | 2 |
| more mature | Dependency Composition Scan | Production · Spring Boot · Code · Pull Request | Available → Automated | 2 |
| more mature | Dependency Composition Scan | Production · Spring Boot · Build · CI Pipeline | Available → Automated | 2 |
| more mature | Dependency Composition Scan | Production · React · Code · Pull Request | Available → Automated | 2 |
| more mature | Dependency Composition Scan | Production · React · Build · CI Pipeline | Available → Automated | 2 |
What changed in what is asked of you
Things we changed: scopes the profile started or stopped asking for, because the control catalog grew or your application's profile moved. Neither is an improvement and neither is a regression.
| What happened | Control | Where | Before → after | Weight |
|---|---|---|---|---|
| newly required | API Security Scan | Development · REST · Test · CI Pipeline | 1 | |
| newly required | API Security Scan | Development · REST · Operate · Continuous Scan | 1 | |
| newly required | API Security Scan | Test · REST · Test · CI Pipeline | 1 | |
| newly required | API Security Scan | Test · REST · Operate · Continuous Scan | 1 | |
| newly required | API Security Scan | Production · REST · Test · CI Pipeline | 1 | |
| newly required | API Security Scan | Production · REST · Operate · Continuous Scan | 1 |

