Search
Free-text and field queries across every indexed entity, from a single command to a single line of YAML.
KvantumCI Release 1.5
Every problem in your pipelines, on one searchable map. Look up a finding, a missing control or an outdated dependency. Atlas is the new visibility layer across all of KvantumCI. Ask a question about your organization and get the answer in seconds.
Introducing Update 1.5
Our biggest release yet.
Every verification run builds a record of your commands, dependencies, tools, findings and fixes. Atlas makes that record searchable. Alongside it: a GitHub App that connects your whole org in one install, Chain Analytics that traces every link across templates and repositories before calling a gap, a CI/CD BOM that maps every pipeline dependency, and an open-source CLI for your terminal, scripts and CI.
N°01 · Search & observability
Atlas indexes everything KvantumCI sees across every connected repository, so you can search and filter it all like one dataset.
Which projects still run npm install instead of a lockfile install?
23 projects · 31 matches
Where do we still ship React older than 18?
12 projects · of 41 using react
Which pipelines actually run Trivy, and which container builds don't?
17 pipelines · 17 of 64 container builds covered
Every finding, across the whole org.
9 findings · 6 projects
Show me the recommended fix, and everywhere it applies.
1 recommendation · applies to 9 findings in 6 projects
- uses: actions/checkout@v4
+ uses: actions/checkout@<full-commit-sha> # v4
Pinning to a full commit SHA means a moved or compromised tag can't change what runs in your pipeline.
What’s on the map
Free-text and field queries across every indexed entity, from a single command to a single line of YAML.
Slice results by project, provider, tool, severity, status or owner until only the answer is left.
See how usage and exposure spread across the estate. When a new CVE lands, one query shows where you're affected.
What’s in the release
Atlas leads the release. Four more upgrades ship with it in v1.5.0, and each one adds to the map.
N°02Integration
Connect your whole GitHub organization with one install. The KvantumCI GitHub App is built for enterprise orgs: install it once, choose your repositories, and KvantumCI keeps up as new repositories appear. There are no personal access tokens to rotate.
N°03Cross-template & cross-repo analysis
Real pipelines are chains. A workflow calls another workflow, a template pulls in a template from a different repository, and the control you care about can sit three links away. Until now, if a pipeline didn't run container scanning itself, the check failed, even when a linked template ran Trivy. Chain Analytics traces every link, across templates and repositories, and reports what it actually finds.
N°04OmniBOM · Provenance
An SBOM tells you what's in your software. The new CI/CD BOM in OmniBOM tells you how it was built. It detects your pipeline dependencies, from the actions, templates and tools to the images every build pulls in, and records the provenance of the pipeline itself as supply-chain evidence you can hand to an auditor.
N°05Command line
The open-source KvantumCI CLI gives you access to the whole platform, in your terminal, in scripts and in CI. The repository also includes a skill you can install, so your coding agent knows how to use the CLI too.
results summary --fail-on-findings exits non-zero on failuresN°01–05One map
Atlas sits on top of the whole platform. Core verification, OmniBOM and AI & MLOps coverage were already there. The GitHub App, Chain Analytics, the CI/CD BOM and the CLI join them in this release, and all of it lands on one searchable map.
Atlas is live in v1.5.0 on every plan. Search your estate today.
Connect your org with the GitHub App, then find every command, dependency, tool and finding with one search. No credit card required.
Patch notes · v1.5.0
Everything that shipped in the Atlas release.