Gradle Technologies is now Develocity — read the announcement

Policy Scan

Treat your toolchain like a production system and prove it.

Feature overview

Policy Scan

Policy Scan evaluates every artifact against your compliance policies at each gate in the delivery pipeline, recording a signed result. Downstream gates read upstream results instead of re-evaluating from scratch, so compliance accumulates as artifacts move through the delivery lifecycle. Dependency health shows which versions carry vulnerabilities, which are outdated, and which need attention. Artifact risk surfaces the moment a new CVE lands, because the attested bill of materials is already known. Cycle time between gates reveals where artifacts stall. Instrument the supply chain and discover what was invisible before.

Inspect an artifact's journey through the supply chain

  • See where any artifact is in the delivery pipeline and what happened at every gate.
  • Measure cycle time between gates, pinpointing where the artifact stalled.
  • Reconstruct the promotion sequence to see exactly when and why each gate advanced.
Learn how policies are evaluated (opens in new tab)
Artifact delivery timeline showing gate progression, cycle time, and production gate blocked by dependency-compliance.

Risk lights up the moment a vulnerability lands

  • Know which release lines carry vulnerable, end-of-life, or outdated dependencies without pulling a single image or re-scanning a build.
  • Set vulnerability remediation and upgrade targets per severity and per package pattern through service-level objectives (SLOs) that default to patch-level upgrades.
  • Author policies as YAML and manage them in git so every change goes through pull-request review like application code.
  • Risk assessment draws from signed attestations the server generates independently. See What is a Fact.
Author declarative policies (opens in new tab)
Dependency risk score of 47 out of 100 beside a Top Actions list of Maven dependencies to upgrade — jackson-databind, log4j-core, and aws-java-sdk-s3 — each with its version bump, vulnerability count, and score impact.
Analytics

Track risk and remediation trends per release line

  • Measure remediation cadence, upgrade trends, and release frequency per release line through the MCP server.
  • RoadmapTrack upgrade cadence per release line to spot aging dependencies before risk compounds.
  • RoadmapCompare release frequency across release lines to identify where delivery bottlenecks form.
  • RoadmapReceive alerts when a release line falls out of SLO compliance before risk compounds.
Release line analytics dashboard showing remediation and release frequency trends.

Surface compliance data in your tools and agentic workflows

  • Your tools, dashboards, and agentic workflows read compliance data through the REST API.
  • Connect AI agents to compliance data without custom integration through the Model Context Protocol (MCP) server.
  • See deployment events, ITSM tickets, and external signals through Fact Connectors and Fact Evaluators.
Explore the REST API (opens in new tab)
Governance data flowing outward through REST API and MCP Server to platform engineering tools and agentic workflows.

Resources

Supply Chain Observability with Develocity Provenance Governor
Blog

What's next

Get started today with a 30-day free trial of the entire Develocity product suite.

Start Free Trial

© 2026 Gradle, Inc. Gradle®, Develocity®, Build Scan®, and the Gradlephant logo are registered trademarks of Gradle, Inc.

Get an AI summary of Develocity: