KvantumCI Release 1.5

Atlas

Out now v1.5.0 Released September 2026

Every problem in your pipelines, on one searchable map. Look up a finding, a missing control or an outdated dependency. Atlas is the new visibility layer across all of KvantumCI. Ask a question about your organization and get the answer in seconds.

See the release

Introducing Update 1.5

Our biggest release yet.

Every verification run builds a record of your commands, dependencies, tools, findings and fixes. Atlas makes that record searchable. Alongside it: a GitHub App that connects your whole org in one install, Chain Analytics that traces every link across templates and repositories before calling a gap, a CI/CD BOM that maps every pipeline dependency, and an open-source CLI for your terminal, scripts and CI.

N°01 · Search & observability

Ask your estate anything.

Atlas indexes everything KvantumCI sees across every connected repository, so you can search and filter it all like one dataset.

Which projects still run npm install instead of a lockfile install?

command:"npm install"provider: any

23 projects · 31 matches

ProjectLocationMatchProvider
payments-api.gitlab-ci.yml:41script: npm install --no-auditGitLab
web-storefront.github/workflows/build.yml:28run: npm installGitHub
mobile-bff.github/workflows/ci.yml:52run: npm installGitHub
docs-site.gitlab-ci.yml:17script: npm installGitLab

What’s on the map

  • Projects
  • Dependencies
  • Pipeline commands
  • CI/CD tools
  • Findings
  • Recommendation snippets
01

Search

Free-text and field queries across every indexed entity, from a single command to a single line of YAML.

02

Filter

Slice results by project, provider, tool, severity, status or owner until only the answer is left.

03

Observe

See how usage and exposure spread across the estate. When a new CVE lands, one query shows where you're affected.

What’s in the release

Five discoveries, one Atlas

Atlas leads the release. Four more upgrades ship with it in v1.5.0, and each one adds to the map.

N°02Integration

GitHub App

Connect your whole GitHub organization with one install. The KvantumCI GitHub App is built for enterprise orgs: install it once, choose your repositories, and KvantumCI keeps up as new repositories appear. There are no personal access tokens to rotate.

  • Org-wide install in a few clicks
  • Grant access to all repositories or a selected set
  • New repositories are picked up automatically
  • Scoped app permissions instead of personal tokens

N°03Cross-template & cross-repo analysis

Chain Analytics

Real pipelines are chains. A workflow calls another workflow, a template pulls in a template from a different repository, and the control you care about can sit three links away. Until now, if a pipeline didn't run container scanning itself, the check failed, even when a linked template ran Trivy. Chain Analytics traces every link, across templates and repositories, and reports what it actually finds.

  • Follows linked workflows and templates, even across repositories
  • Fewer false failures on templated pipelines
  • A real gap is still reported, with every link that was checked
  • Works with the rules you already run, with no config changes

N°04OmniBOM · Provenance

CI/CD BOM

An SBOM tells you what's in your software. The new CI/CD BOM in OmniBOM tells you how it was built. It detects your pipeline dependencies, from the actions, templates and tools to the images every build pulls in, and records the provenance of the pipeline itself as supply-chain evidence you can hand to an auditor.

  • Detects pipeline dependencies: actions, templates, tools and images
  • Provenance for every build path
  • Sits alongside SBOM, CBOM, AIBOM and MLBOM in OmniBOM
  • Fully searchable in Atlas
Explore OmniBOM →

N°05Command line

KvantumCI CLI

Open source on GitHub

The open-source KvantumCI CLI gives you access to the whole platform, in your terminal, in scripts and in CI. The repository also includes a skill you can install, so your coding agent knows how to use the CLI too.

  • Open source: read it, audit it, contribute to it
  • Projects, repositories, verifications, BOMs and findings from one command line
  • A CI gate: results summary --fail-on-findings exits non-zero on failures
  • Agent-safe by design: no deletes, credential writes or admin changes
  • An installable skill for coding agents, in the same repository

N°01–05One map

Everything, on one map

Atlas sits on top of the whole platform. Core verification, OmniBOM and AI & MLOps coverage were already there. The GitHub App, Chain Analytics, the CI/CD BOM and the CLI join them in this release, and all of it lands on one searchable map.

Atlas is live in v1.5.0 on every plan. Search your estate today.

Chart your estate

Connect your org with the GitHub App, then find every command, dependency, tool and finding with one search. No credit card required.

Patch notes · v1.5.0

Atlas — full patch notes

Everything that shipped in the Atlas release.

Atlas

  • Search: Free-text and field queries across projects, dependencies, pipeline commands, CI/CD tools, findings and recommendation snippets.
  • Filter: Narrow results by project, provider, tool, severity, status or owner.
  • Observe: See how tool usage, dependencies and exposure spread across the estate.
  • Available on all plans.

Integrations & developer tools

  • GitHub App: Install once for an entire GitHub organization, with all or selected repositories.
  • KvantumCI CLI (open source): Access to the KvantumCI platform from terminals, scripts and CI, covering projects, repositories, integrations, verifications, BOMs and findings. Agent-safe scope with no deletes, credential writes or admin changes.
  • Agent skill: The CLI repository includes an installable skill that shows coding agents how to use the CLI.

Rule engine & OmniBOM

  • Chain Analytics: When a control such as container scanning is missing from a pipeline, the rule now follows linked workflows and templates, including ones in other repositories, and reports whether the control was found further down the chain.
  • Fuzz testing rule: New rule that detects fuzzing in CI/CD pipelines and reports when it's missing.
  • CI/CD BOM: New OmniBOM type that detects pipeline dependencies (actions, templates, tools and images) and records the provenance of every build.