Pitangus

Bugs caught while you read: 0 bugs caught

EspañolCode

Plate I·Pitangus sulphuratus

Watch every change.Prove every fix.

Self-hosted application security for small teams. Pitangus scans your code, dependencies and secrets, tells you what each change introduces and what it fixes, and keeps the evidence an auditor can check.

  • Open source · AGPL-3.0
  • Runs on your server
  • No telemetry
Fig. 1 — Pitangus sulphuratus (Linnaeus, 1766)Habitat: your repositories. Diet: bugs.

Field guide

Every bug, catalogued like a specimen.

Seven open engines you already trust look at your code, dependencies, secrets, infrastructure and images. Pitangus merges what they find, removes duplicates and files each finding with where it lives and how to fix it.

Opengrep · Gitleaks · Trivy · OSV-Scanner · Grype · Checkov · zizmor

  1. № 01Code

    CWE-89

    SQL injection

    app/db.py:14

    Request input reaches a query built as text.

  2. № 02Dependency

    CVE-2021-23337

    lodash 4.17.15

    package-lock.json

    Update to 4.18.0: it closes all six advisories.

  3. № 03Secret

    CWE-798

    GitHub token

    config/settings.py:3

    Revoke it first. Its value never leaves your server.

  4. № 04Infrastructure

    CKV_AWS_20

    Public bucket

    infra/s3.tf:8

    Anyone could list it. Block public access.

Pull requests

Only what your change brings. And what it fixes.

In CI, Pitangus scans the starting point and your change with the same engines, so a pull request is judged only by what it adds. It also says what the change fixed, and credits it only when both scans finished and the file really changed.

One step in your workflow

- uses: actions/checkout@v4
  with: { fetch-depth: 0 }
- uses: Pitangus-Dev/pitangus@v0.12.0

The official GitHub Action runs the published image: no build, no Docker socket.

$ pitangus scan --base main
Pitangus · api · changes since main (merge-base 4f2a9c1e, 1 file) No new findings. Fixed by this change (1): it was in the starting point, it’s gone, and its file changed.  HIGH     app/db.py:14  SQL injection from request input PASS · threshold: high or above · No new findings in the code that changes

The ledger

Fixed means verified. Not assumed.

Each finding keeps its history: when it appeared, who triaged it and why, its deadline from your policy, and the scan that proved it gone. Decisions are recorded, not overwritten.

FindingStatusDeadline
SQL injection · app/db.py:14FixedOct 20
lodash 4.17.15 · 6 vulnerabilitiesOpenOct 30
Public bucket · infra/s3.tfAccepted riskUntil Dec 1
  • i

    Deterministic

    The same code, engines and advisory data give the same result. An auditor can repeat it.

  • ii

    Evidence

    SBOM (CycloneDX), VEX (OpenVEX), SLA reports and an audit trail of every decision.

  • iii

    Honest about gaps

    If an engine fails, the scan says so, and nothing that engine looks at counts as fixed. It never reads as “no findings”.

Any tool, one ledger

Bring what other tools find.

Import SARIF from any scanner or AI reviewer. Its findings join the same registry, with triage, deadlines and tickets. Only a new full import from that same tool can mark them fixed: each tool vouches for what it looks at.

  • SARIFSemgrep
  • SARIFCodeQL
  • SARIFSnyk
  • SARIFTrivy
  • SARIFGrype
  • SARIFBandit
  • SARIFESLint
  • SARIFStrix
  • SARIFAny SARIF 2.1.0

Jira

Tickets a developer can act on.

Issues go to the right project for each repository, with your custom fields. They say what is wrong, where, how to fix it, how to verify it and by when. When the fix is verified, Pitangus comments on the issue.

SEC-142

High: update lodash 4.17.15 to 4.18.0 (6 vulnerabilities)

The problem
lodash 4.17.15 has 6 known vulnerabilities. Version 4.18.0 fixes all of them.
Where
acme/web · package-lock.json
How to fix it
npm install lodash@4.18.0
Due date
Oct 30, from your security policy
VERIFIED

Verified as fixed by Pitangus in scan 9f3c… on Oct 2.

Yours

Runs on your server. Speaks your language.

  • i

    Self-hosted

    One server with Docker and 4 GB of memory. Your code and findings stay with you.

  • ii

    Open source

    AGPL-3.0. Read every line, change it, run it without asking.

  • iii

    English and Spanish

    Written for each language, not machine-translated. Reports, PR comments and tickets included.

  • iv

    No telemetry

    Nothing phones home. It only reaches out for public advisory data and, if you connect them, GitHub and Jira.

Install

Five minutes, one server.

  1. 1You need Docker, make and git.

  2. 2Start it and open the panel.

    git clone --branch v0.12.0 https://github.com/Pitangus-Dev/pitangus.git
    cd pitangus
    make setup PREBUILT=1
    make up
  3. 3Or add the Action to your workflow.

    - uses: Pitangus-Dev/pitangus@v0.12.0

Read the docs Free and open source (AGPL-3.0). It runs on your server: no account, no telemetry.