Free trial · 14 days · Cancel anytimeGet started

Pierrr Security

Automated vulnerability scanning for every project, on demand or on a schedule.

Last updated: September 8, 2026

What it scans

A scan covers every container of the project at once. Two scanners work in parallel on each of them:

  • The image built for the container, its system packages and the dependencies it ships, checked against published vulnerabilities.
  • The application source code, through static analysis, for code patterns known to be dangerous.

Both sets of results are merged into a single scan: there is no second run to start, and no second report to cross-check.

Running a scan

Open a project's Security tab, then click Scan now. The scan is queued and then starts running; the page follows its progress without you reloading it. A counter above the history shows how many scans you have used this month and your plan's limit.

A scan goes through four states: queued, running, completed, failed. Every history row also shows how it was triggered, manually or on a schedule.

Scheduled scans

Rather than remembering to do it, let Pierrr come back to the project at a regular interval. The Scheduled scans block of the Security tab asks for three settings:

  • The frequency, daily or weekly.
  • The day of the week, for a weekly schedule.
  • The hour it runs, expressed in UTC.

An extra option emails you a summary after each scheduled scan. Those scans draw on the same monthly quota as the ones you start by hand.

Reading the results

The history lists every scan with its status, its trigger, its start time and the count of findings per severity. Open one for the detail, one row per finding:

  • The severity: critical, high, medium or low.
  • The container it affects, so you can place the finding in a project that has several.
  • A description of the finding and, for a dependency vulnerability, the package at fault.
  • The installed version and the fixed version, when the scanner knows of one.
  • A link to the original security advisory, so you can judge the real impact on your application.

A selector narrows the list to a single container, and a search field filters on the vulnerability identifier, the package name, the version or the container. A counter shows how many rows matched out of the total.

Every completed scan can be downloaded as a PDF, to archive it or hand it to someone without console access.

How long results are kept

A scan and its findings are kept for 30 days, then deleted automatically. Download the PDF if you need a record beyond that.

Available plans

Pierrr Security is included from the Pro plan. Free and Starter organizations see an upgrade prompt instead of the scan controls.

The quota is monthly and resets each month: 10 scans on the Pro plan, 50 on Business. Only scans that run to completion count against it, so a failed scan costs you nothing.