WoluTools

Release Security Pack Scanner

Release Security Pack Scanner Online: inspect a release bundle before it leaves the team.

Create a release evidence pack without uploading code to a third-party scanner.

START HEREChoose documentsZIP, TAR, TAR.GZ, TGZ, JSON, YAML, YML
Maximum
5 files · 64 MB total
File handling
Draft 2 hours · encrypted result 24 hours
FREE3 jobs a dayFiles up to 10 MB
PROUp to 200 jobs a day€12.99/month or €89.99/year
See plans

Larger files need Pro. Failed jobs are never counted.

  • Prepared example is free
  • 3 free jobs a day
  • Cancel anytime
EXAMPLE RESULTSample data
Components · 312
2
4
312
IaC blockers · 4
Six static release findings need reviewHTML, SARIF, CycloneDX or SPDX, protected CSV and engine manifest
Components
312
Secret candidates
2
IaC blockers
4
Formats, limits & file handling
Works with
ZIP, TAR, TAR.GZ, TGZ, JSON, YAML, YML
Limit
5 files · 64 MB total
You receive
HTML, SARIF, CycloneDX or SPDX, protected CSV and engine manifest
File handling
Draft 2 hours · encrypted result 24 hours

Create a release evidence pack without uploading code to a third-party scanner.

THREE CLEAR STEPS

From your documents to a usable result.

  1. 01
    Add your input

    Limits and supported formats are visible before you begin.

  2. 02
    Review the result

    Check the preview, findings or artwork before you download.

  3. 03
    Download

    Use your free job, plan or credits. Failed jobs are never counted.

Prepared result preview

See the decision before sharing a real file.

Create a release evidence pack without uploading code to a third-party scanner. This prepared example uses fictional data and the same evidence structure as the server export.

✓
Nothing is uploadedPublic demo only

Release assurance

Six static release findings need review

This static rules snapshot has no CVE database and never claims vulnerability completeness or that the release is secure.

Actual prepared coverage: 1 source archive · 2 supplied SBOMs · pinned static rule snapshot

  • UrgentCredential pattern in release sourceconfig/deploy.env · line 18 · value redacted
  • ImportantContainer runs as rootdeploy/Dockerfile · USER instruction missing
  • BoundaryNo CVE databaseDependency inventory is parsed, but vulnerability completeness is not tested
Components
312
Secret candidates
2
IaC blockers
4
Show the verified package

HTML, SARIF, CycloneDX or SPDX, protected CSV and engine manifest

Engine release-security-v2 · rules cyclonedx-spdx-profile-auth-2026-08-31

One focused workflow

From bounded input to evidence you can review

  1. Add the source.Accepted inputs are ZIP, TAR, TAR.GZ, TGZ, JSON, YAML, YML. The visible limit is 5 files · 64 MB total.
  2. Confirm the job.Every assigned source number, selected filename and setting stays visible before the confirmed SHA-256 input hash is accepted. Product-specific mappings remain explicit settings rather than guessed roles.
  3. Process in isolation.A one-job networkless sandbox receives only this job and cannot access accounts, queues, encryption keys or other customer storage.
  4. Review exact findings.Review source archives, supplied SBOMs and IaC files for exposed-secret patterns, risky configuration and dependency inventory evidence with pinned offline rules.
  5. Download the evidence.HTML, SARIF, CycloneDX or SPDX, protected CSV and engine manifest Every output hash is covered by the coordinator-created manifest.

What this product does not claim

This static rules snapshot has no CVE database and never claims vulnerability completeness or that the release is secure.

Clear answers

Release Security Pack Scanner FAQ

What can I submit?

Source archives as ZIP, TAR, TAR.GZ or TGZ, plus SBOM and IaC files as JSON, YAML or YML. Up to five files and 64 MB per job.

Does it look up known vulnerabilities?

No. There is no CVE database behind this scan. Dependencies are inventoried from the manifests and SBOMs you supply, but vulnerability coverage is neither tested nor claimed.

What kind of findings come back?

Exposed-secret patterns with the file and line and the value redacted, plus risky configuration such as a Dockerfile with no USER instruction.

Why might a real secret be missed?

Detection uses a pinned offline rule set, so a credential in an unusual format or beyond the scanned budget will not match. Treat the output as a review list, not as a sign-off on the release.

What is in the download?

An HTML report, SARIF for your pipeline, a CycloneDX or SPDX inventory, a protected CSV and an engine manifest naming the rule version that ran.

Available now

Inspect a release bundle before it leaves the team.

Inspect the fictional result now. Your own files run here without an account: 3 free jobs a day, or up to 200 a day with Pro.