Platform Use Case

Vulnerability Management -The Ortelius Open Source Project

Ortelius is the open-source project behind DeployHub’s post-deployment vulnerability management capabilities. DeployHub hosts a free SaaS version of Ortelius for small teams and also offers the commercial DeployHub platform for organizations that need enterprise scale, governance, and support.

Platform

The Risk

Don’t Wait for a New CVE to Find Out You’re Exposed

Software that was secure when it was deployed can become vulnerable overnight. Without post-deployment visibility, teams may not know which newly disclosed CVEs affect their live applications, where vulnerable components are running, or how far the exposure reaches.

Ortelius gives you a free, open-source way to close that visibility gap now. Start with the hosted SaaS version, connect your software data, and begin identifying real production risk in minutes—before the next vulnerability turns into an incident.

Vulnerability Management Platform for Post-deployment Defense

From discovering where open-source packages are being used, to federating OpenSSF Scorecard, Ortelius.io serves as a central hub for vulnerability detection so teams can trust the open-source they rely on from code to cloud. Free to use, incubating at the Continuous Delivery Foundation, with a SaaS offering hosted by Deployhub.

Open Governance Under the Linux Foundation Ecosystem

Want to use Ortelius?

Start free and see which vulnerable packages are actually running across your applications and endpoints.

Chat With the Community on Discord

Chat with the Ortelius vulnerability detection community.  Ask them anything.

Want to contribute?

Join the community, explore issues, attend meetings, test features, improve documentation, or help shape the roadmap.

The Ortelius vulnerability management open source tool is an open source project at the Continuous Delivery Foundation, part of the Linux Foundation ecosystem.

The project follows open governance and community-driven development. Contributors from any organization can participate, propose ideas, contribute code, and help shape the direction of the project.

That independence helps keep Ortelius open, interoperable, and driven by the needs of its users and contributors.

continuous delivery foundation

Built by the Open-Source Community

Ortelius brings together contributors from cybersecurity, DevOps, platform engineering, AI, software supply chain security, and open-source governance. The project is shaped by people who use the software, test new ideas, report problems, improve documentation, build integrations, and contribute code. You do not need to be a core developer to participate. Some of the most valuable contributions come from practitioners who can tell us where vulnerability management breaks down in the real world.

Why Contribute to Ortelius?

Contributing to Ortelius gives you the opportunity to work on real problems in software supply chain security and post-deployment vulnerability management.

Community members can:

  • Build experience with SBOMs, CVEs, dependency intelligence, and software provenance
  • Learn cloud-native and DevSecOps architecture
  • Work alongside practitioners from security, platform engineering, and open-source communities
  • Develop technical and leadership skills
  • Gain recognition for meaningful open-source contributions
  • Help define how teams detect and remediate vulnerabilities after deployment

Find Your Way to Contribute

There are many ways to contribute to Ortelius:

  • Use the platform and share feedback about what works and what is missing.
  • Report issues and help reproduce bugs.
  • Test new releases and validate new capabilities.
  • Improve documentation and tutorials.
  • Contribute code to vulnerability intelligence, SBOM, deployment, and remediation capabilities.
  • Build integrations with CI/CD, security, and cloud-native tools.
  • Help with outreach through blogs, talks, events, and community programs.
  • Join architecture discussions and help shape technical direction.
  • Become an adopter and influence the roadmap with real-world requirements.

Try the Free SaaS Environment Hosted by DeployHub

Our free SaaS offering gives teams a hosted version of Ortelius to identify which open-source vulnerabilities are affecting deployed software, locate where vulnerable components are running, and focus on the risks that matter most. No budget approval required, with actionable value in 10 minutes or less.

Use the DeployHub Free SaaS to:

  • Detect newly disclosed vulnerabilities affecting released software
  • Consolidate SBOM intelligence across applications
  • Search for open-source packages across endpoints
  • See where vulnerable components are running
  • Understand vulnerability blast radius
  • Track software across deployment environments
  • Evaluate open-source project security with OpenSSF Scorecard

Solution Benefits

Detect post-deployment CVEs

Continuously identify newly disclosed vulnerabilities that affect software already running in production, even if those CVEs did not exist when the software was built.

Locate vulnerable components

See which applications, environments, and endpoints contain an affected open-source package so teams know exactly where remediation is needed.

Consolidate SBOM intelligence

Combine component data from multiple services, repositories, and artifacts into a unified application-level view of packages, versions, licenses, and vulnerabilities.

Understand blast radius

Quickly determine how broadly a new vulnerability affects deployed software, including the applications, environments, and endpoints that may be exposed.

Track deployed software

Maintain visibility into what software is running and where it is deployed without installing or managing persistent endpoint agents.

Prioritize real production risk

Focus on vulnerabilities tied to software that is actually deployed instead of spending time investigating every CVE found in source code, repositories, or unused components.

Start free in minutes

Use the hosted Ortelius SaaS environment without procurement delays or budget approval and begin gaining post-deployment vulnerability visibility in 10 minutes or less.

Contribute and influence the roadmap

Join the open-source community to test features, report issues, improve documentation, contribute code, and help shape the future of post-deployment vulnerability management.

Need enterprise scale?

DeployHub extends the Ortelius open-source foundation with enterprise access controls, broader component coverage, and commercial support.

Whitepaper Download

The Ortelius Vulnerability Management Open-Source Tool

Platform Comparison

Here’s how the Ortelius OS Vulnerability Management platform compares to Traditional SCA, Scanners, and SAST.

CapabilityOrteliusTraditional SCAContainer ScannersSAST
Maps CVEs to deployed applicationsYesLimitedContainer-onlyNo
Shows where vulnerable packages are runningYesNoLimitedNo
Tracks ownership and blast radiusYesLimitedLimitedNo
Uses SBOMs after deploymentYesLimitedLimitedNo
Supports agentless operational visibilityYesUsually noUsually noNo

Our Partners

catalyst campus
sda tap lab logo