Work with Spectra Resolve
A typical Spectra Resolve workflow begins by selecting an existing software project with a supported manifest file.
In the background, Resolve relies on rl-protect to scan the packages defined in the manifest file.
You can set a number of parameters for the scan and choose which actions the AI agents should handle after the scan.
Scanning results are delivered as an interactive report that you can explore in the Resolve interface. The report is also the starting point for issue triage and remediation, which you can perform with the help of AI agents configured on your system.
In the Resolve interface, you can always access the settings, your projects, saved chats with AI, and any pending tasks from the sidebar on the left.
This guide covers basic information about the features available in Spectra Resolve. For a more detailed walkthrough, refer to our tutorial video.
Organize your repositoriesโ
Spectra Resolve distinguishes between projects and repositories.
A project is a logical way to organize and group your repositories (folders). For example, if you are developing multiple applications for a client, the project name can correspond to your client's name.
When you create a project in Resolve, you can configure default scanning settings that will apply to all repositories added to the project. You can change the following settings:
- Connection - which of the configured connections to use for connecting to ReversingLabs APIs
- Profile - which of the preset profiles to use for scanning manifest files
- Dependencies - which types of dependencies to include in the scan
A repository represents a folder on your system that contains one or more manifest files you want to scan. It is analogous to the concept of a code repository in version control systems.
When you add a repository to Resolve, it automatically discovers supported manifest files in the selected folder. You can later choose which manifest file to use for each scan. Additionally, you can change the scanning settings for every added repository to override defaults configured for the project. Every repository keeps its settings, reports, and pending tasks separate from other repositories in the project.
Run a scanโ
To run a scan in Spectra Resolve, select one of the added repositories (folders). You can then select the following parameters before starting or scheduling a scan:
-
Manifests - lists every supported manifest file found in the folder. Select one or more files to scan. It's recommended to select a lock file when available
-
Profile - lets you choose which scanning profile to use. Select one of the preset profiles or create a custom one. Open Source [hardened] is the default
-
Dependencies - lets you select which types of dependencies should be included in the scan, and to which depth level. Release or Development must stay selected
-
Approvals - instructs the AI agents how to behave when they need to run a command. If you don't respond to an approval request, the request times out and the command does not run
| Option | Description |
|---|---|
| Ask every time | Every command opens the approval dialog |
| Auto approval (default) | Commands that are considered safe run on their own. Installs, tests, scripts and file changes are checked by an approver tool against, and you are asked only when it is unsure or a command reaches outside the project |
| Approve all | Every command runs without asking for approval. This option is not recommended for beginner users |
- What to do - lets you select the actions to perform during and after the scan
| Option | Description |
|---|---|
| Assess findings | Always selected. The CLI tool rl-protect scans packages defined in the selected manifest files, then classifies the evidence and checks package-level reachability |
| Triage findings | AI agent rules out what cannot be reached to help you focus only on exploitable issues |
| Investigate malware | AI agent traces how a malicious package could reach your code (runs only if malware is found) |
| Remediate issues | AI agent identifies safe dependency upgrades, each verified by a re-scan and a behavior diff |
After modifying the desired settings, you can either select the option to start the scan immediately or schedule it as a recurrent re-scan.
Spectra Resolve creates a hidden .rl-protect/ folder inside every repository, where it keeps the remediation plan, the analysis reports, and a history of the last 30 scans per folder.
If the folder you select to scan is a git repository, Resolve automatically offers to add .rl-protect/ to
your .gitignore file.
While the scan is in progress, you can see the current stage it's in and view more detailed information in the agent log. Depending on the selected actions and the amount of issues detected, you may be prompted to choose which types of vulnerabilities to triage as a way to preserve tokens.
If necessary, you can stop the scan at any time.
Some scans may take longer to complete, depending on the size and complexity of your software project, the selected scan settings, and the configured AI model.
When the scan is complete, you can see how many tokens were spent on the last scan run and open the analysis report. You can also access the Worklist in the sidebar to get a more detailed overview of actions performed by agents on every package. The Worklist is useful for auditing purposes, but you can also use it as a starting point for exploring remediation actions and fixing issues.
Understand the reportโ
The analysis report is a local file in the hidden .rl-protect/ folder that is not shared anywhere outside of your system.
Since it's a self-contained HTML file, you can copy it from that folder anywhere else, and view it in a web browser without having to open Spectra Resolve.
The report is divided into the following sections:
-
Summary - overall risk verdict with counts about packages and findings. Depending on actions performed and issues detected during analysis, this section also contains information about vulnerability triage and remediation, package age, vulnerability lifecycle, and license compliance.
-
Packages - list of all analyzed packages with information about their status, detected issues, and policy violations. For every package in the list, you can select the option to accept risk, fix it with AI or start a chat with AI. If you have scanned multiple manifest files, you can switch between them in this section to view their respective packages.
-
Findings - detailed information about every analyzed package (version, provenance, issues, available upgrade versions), including policy checks and reachability analysis with evidence for detected issues. Detected issues are grouped into SAFE assessment categories. Depending on the types of detected issues, you can select options to upgrade or downgrade the package to different versions, accept risks, triage issues, ask AI or fix issues with AI. For every package, you can access the full report on Spectra Assure Community, and show the package in the dependency tree to understand how it is being used in your project.
-
Appendix: Excluded Findings - if anything is triaged out, accepted or suppressed, it is listed here with details about the reason for exclusion.
Every analysis report provides a number of options to interact and collaborate with AI agents. You can start a chat about the current report by selecting the pill button with the agent name in the upper right corner. Additionally, nearly every item in the report has the option to ask AI for help or more information. As the amount of detail in the reports may be time-consuming to parse manually, it's always recommended to use the AI to summarize risks and clarify the best path forward.
Plan and apply changesโ
You can act on every detected issue in the analysis report, and the Spectra Resolve interface offers multiple ways to achieve that:
-
From the Packages section, you can choose to accept risks or fix issues with AI for each individual package. Alternatively, select the rocket icon (๐) to enter the Planning mode, where you can decide on a task for each package and add it to the plan. If you select the Auto sort button, the AI agent will make those decisions automatically for you.
-
From the Findings section, you can drag each package card to the bottom of the Resolve window and select one of the tasks to add to the plan.
Spectra Resolve shows informative tooltips if the selected task is not available or not appropriate for a specific issue.
| Task | Description |
|---|---|
| Accept | Records an audited risk acceptance with your statement, your name, a timestamp, and any compensating controls. Acceptance is always a human decision; no agent can make it |
| Triage | The AI agent cross-references the finding against advisories and reachability, and records a verdict in the plan |
| Upgrade | The AI agent upgrades the package to a version you selected and performs a re-scan. If the selected version introduces new risk, the upgrade is rejected |
| Fix | The AI agent proposes a remediation, which you can validate and apply |
All selected tasks are added to the plan. Before executing the plan, you can expand the tasks to view the full list, remove them manually or clear the whole list at once.
When you choose to execute a plan, AI agents run commands in the background to perform the tasks you selected. If actions are performed on several findings at once, Spectra Resolve processes each one but performs at most one re-scan after they have all been processed.
Automate actionsโ
Instead of manually running scans and fixing issues in each individual repository, you can use the Run agents option when you select one or more repositories on the project page.
This allows you to configure how the agents will behave, which actions they will perform, and when to ask for your approval.
| Option | Description |
|---|---|
| Autonomous | AI agents perform full analysis on every selected folder, including assessment, triage, investigation, and looking for upgrades, regardless of each folder's existing settings. No fixes are applied |
| Autonomous + Fix | AI agents perform full analysis on every selected folder. Then, the remediator agent applies validated fixes and commits changes to the plan and report |
| Configured | AI agents perform actions according to each folder's existing settings |
Schedule and compare scansโ
Spectra Resolve preserves information about every scan (including the report and all metadata) and stores the last 30 scans for every repository. If the repository you select has had multiple scans performed, you can view and compare changes between the latest and previous scan, or between the current scan and any other scan in the History list.
To keep the scan results up to date, you can set up recurring re-scans with the Schedule option when you select a repository. You can choose to run scans daily, weekly, or monthly, and use the option Catch up on launch to perform a re-scan when you open Spectra Resolve if it was skipped while the application was closed. Scheduled re-scans only refresh the report. AI agent actions never run unattended.
Get insights from AIโ
In addition to collaborating with AI agents on every individual analysis report, you can use the New chat option in the Spectra Resolve sidebar to get insights on your overall security status through a conversational interface. You can limit the scope of every chat to all projects, current project, or current folder.
To get started, choose any of the suggestions in the chat, or ask your own questions about packages, reports, issues, and tasks. You can also ask about packages not currently present in any of your projects to assess if they are safe to adopt. In this case, the AI suggests exploration, which performs a scan and requires your confirmation because it consumes quota. The result of exploration is a package card you can compare against the packages you currently use.
The AI includes citations and links in the answers to help you understand the evidence and access the source of its claims. Every chat is automatically saved and can receive answers even when it's not selected as active in the Resolve interface. You can rename and delete chats at any time.