Skip to content

What you can do with Relane

Practical ways to use Relane Security for engineering reviews, vulnerability remediation and clear stakeholder reporting.

For developers: turn a finding into a changePermalink to For developers: turn a finding into a change

Start with the code you own. Review the affected file and line, the evidence behind the finding and the suggested remediation. For an eligible dependency issue, open its fix workspace to inspect the proposed changes before approving a pull request. For other issues, use the finding as a focused engineering handoff and assess the updated code after your change.

For security teams: focus attention with contextPermalink to For security teams: focus attention with context

Review confirmed findings separately from leads that still need validation. Use severity to prioritize investigation, coverage to understand the assessment's limits, and triage to record decisions about false positives or accepted risks. Repository policies make the team's acceptance criteria explicit instead of relying on an informal interpretation of a finding count.

For engineering leaders: make the handoff clearPermalink to For engineering leaders: make the handoff clear

Use the assessment report to explain what was assessed, what was found and what remains unresolved. Give engineers the technical detail and stakeholders a summary with the same underlying scope. Shared workspaces keep repositories and assessment history with the team rather than with one person's account.

Make security a repeatable practicePermalink to Make security a repeatable practice

  1. Establish a baseline

    Assess an authorized repository and save the scope and result for reference.

  2. Agree on the next actions

    Review confirmed findings, investigate uncertain leads and record explicit triage decisions.

  3. Keep the team informed

    Configure a schedule, a repository policy and the notification destinations your team uses.

  4. Check the outcome

    Review the next actual execution and delivery receipt. A saved schedule or destination is configuration, not proof that a scan or notification ran.

Describe Relane accuratelyPermalink to Describe Relane accurately

Relane Security brings repository assessment, evidence-backed findings, reviewed remediation and team reporting into one workflow. Its value is helping teams make and follow through on security decisions, not simply producing a larger list of alerts.

When sharing a result or describing the product, name the assessed scope and the action that actually happened. A reviewed proposal is not a merged fix, a merged fix is not a verified resolution, and a result with no findings is not a guarantee that software is secure. Use the relevant report and verification state to support the claim.