This roadmap communicates direction rather than a delivery guarantee. Security fixes and community needs may change priorities. Work is accepted only through reviewed issues and pull requests.
- Complete OpenSSF Best Practices Silver readiness and evidence.
- Expand enterprise Azure coverage while preserving low false-positive rates.
- Improve scanner inventory error handling and rule test coverage.
- Reconcile documentation, website rule counts and current APIs.
- Stabilize the scanner and REST API contracts for a supported 1.0 release.
- Improve deployment, upgrade and database migration guidance.
- Expand Sentinel detections and operational security monitoring.
- Establish signed release artifacts and public verification instructions.
- Add organization-scale scanning and clearer multi-subscription workflows.
- Improve accessibility and internationalization readiness in user interfaces.
- Expand evidence-based compliance reporting and exception handling.
- Evaluate a provider interface for future clouds without weakening Azure support.
- Review reliability, performance and recovery objectives using production feedback.
- Mature compatibility, deprecation and long-term maintenance policies.
- Reassess readiness for OpenSSF Gold without claiming it prematurely.
- Automatic remediation without explicit operator confirmation.
- Claims of formal certification for CIS, ISO 27001, SOC 2 or NIST.
- Collection of Azure resource contents, secrets or customer workload data.
- Guaranteed detection of every cloud vulnerability or configuration risk.
- Multi-cloud parity until the Azure implementation and provider boundary are stable.