Skip to content
  1. History

History

Every completed assessment for this application, what each one concluded, and what changed between any two of them. Both sides of a comparison are frozen records, so the catalog growing since cannot move either number.

Completed runs

Completed runs
CompletedKindCoverageMovedRecordedCompare
September 8, 2026Review47%+4.4 points250 scopes recorded
as earlieras later
June 9, 2026Self-assessment43%244 scopes recorded
as earlieras later

The worked example carries two runs: an initial self-assessment and a review three months later, after container image scanning and automated dependency updates were introduced and the pull-request gate was made blocking.

Comparing Jun 9, 2026 with Sep 8, 2026

43% → 47%

36 scopes changed in your setup, and the profile changed what it asks for in 6 scopes.

6 scopes became required. A coverage figure that moved for that reason moved because the profile changed, not because the work did.

What changed in your setup

Things you control: a scope something now covers, something that stopped covering one, a control that enforces harder or softer, a process that matured.

What changed in your setup
What happenedControlWhereBefore → afterWeight
gainedContainer Image Vulnerability ScanDevelopment · Docker · Build · CI Pipelinenothing → Trivy image scan in CI and registry2
gainedContainer Image Vulnerability ScanDevelopment · Docker · Build · Registrynothing → Trivy image scan in CI and registry2
gainedContainer Image Vulnerability ScanTest · Docker · Build · CI Pipelinenothing → Trivy image scan in CI and registry2
gainedContainer Image Vulnerability ScanTest · Docker · Build · Registrynothing → Trivy image scan in CI and registry2
gainedContainer Image Vulnerability ScanProduction · Docker · Build · CI Pipelinenothing → Trivy image scan in CI and registry2
gainedContainer Image Vulnerability ScanProduction · Docker · Build · Registrynothing → Trivy image scan in CI and registry2
gainedAutomated Dependency UpdatesDevelopment · Java · Code · Pull Requestnothing → Renovate dependency update pull requests1
gainedAutomated Dependency UpdatesDevelopment · Spring Boot · Code · Pull Requestnothing → Renovate dependency update pull requests1
gainedAutomated Dependency UpdatesDevelopment · React · Code · Pull Requestnothing → Renovate dependency update pull requests1
gainedAutomated Dependency UpdatesTest · Java · Code · Pull Requestnothing → Renovate dependency update pull requests1
gainedAutomated Dependency UpdatesTest · Spring Boot · Code · Pull Requestnothing → Renovate dependency update pull requests1
gainedAutomated Dependency UpdatesTest · React · Code · Pull Requestnothing → Renovate dependency update pull requests1
gainedAutomated Dependency UpdatesProduction · Java · Code · Pull Requestnothing → Renovate dependency update pull requests1
gainedAutomated Dependency UpdatesProduction · Spring Boot · Code · Pull Requestnothing → Renovate dependency update pull requests1
gainedAutomated Dependency UpdatesProduction · React · Code · Pull Requestnothing → Renovate dependency update pull requests1
strongerSAST Pull Request GateJava · Code · Pull Requesta warning → blocking3
strongerSAST Pull Request GateSpring Boot · Code · Pull Requesta warning → blocking3
strongerSAST Pull Request GateReact · Code · Pull Requesta warning → blocking3
more matureDependency Composition ScanDevelopment · Java · Code · Pull RequestAvailable → Automated2
more matureDependency Composition ScanDevelopment · Java · Build · CI PipelineAvailable → Automated2
more matureDependency Composition ScanDevelopment · Spring Boot · Code · Pull RequestAvailable → Automated2
more matureDependency Composition ScanDevelopment · Spring Boot · Build · CI PipelineAvailable → Automated2
more matureDependency Composition ScanDevelopment · React · Code · Pull RequestAvailable → Automated2
more matureDependency Composition ScanDevelopment · React · Build · CI PipelineAvailable → Automated2
more matureDependency Composition ScanTest · Java · Code · Pull RequestAvailable → Automated2
more matureDependency Composition ScanTest · Java · Build · CI PipelineAvailable → Automated2
more matureDependency Composition ScanTest · Spring Boot · Code · Pull RequestAvailable → Automated2
more matureDependency Composition ScanTest · Spring Boot · Build · CI PipelineAvailable → Automated2
more matureDependency Composition ScanTest · React · Code · Pull RequestAvailable → Automated2
more matureDependency Composition ScanTest · React · Build · CI PipelineAvailable → Automated2
more matureDependency Composition ScanProduction · Java · Code · Pull RequestAvailable → Automated2
more matureDependency Composition ScanProduction · Java · Build · CI PipelineAvailable → Automated2
more matureDependency Composition ScanProduction · Spring Boot · Code · Pull RequestAvailable → Automated2
more matureDependency Composition ScanProduction · Spring Boot · Build · CI PipelineAvailable → Automated2
more matureDependency Composition ScanProduction · React · Code · Pull RequestAvailable → Automated2
more matureDependency Composition ScanProduction · React · Build · CI PipelineAvailable → Automated2

What changed in what is asked of you

Things we changed: scopes the profile started or stopped asking for, because the control catalog grew or your application's profile moved. Neither is an improvement and neither is a regression.

What changed in what is asked of you
What happenedControlWhereBefore → afterWeight
newly requiredAPI Security ScanDevelopment · REST · Test · CI Pipeline1
newly requiredAPI Security ScanDevelopment · REST · Operate · Continuous Scan1
newly requiredAPI Security ScanTest · REST · Test · CI Pipeline1
newly requiredAPI Security ScanTest · REST · Operate · Continuous Scan1
newly requiredAPI Security ScanProduction · REST · Test · CI Pipeline1
newly requiredAPI Security ScanProduction · REST · Operate · Continuous Scan1