Version 2.14
Merge rules per fix type
Pick how many approvals each kind of fix needs, and from which team.
Until now every fix pull request needed the same approvals. Merge rules let you set a different quorum per fix type: two approvals from platform for secrets, one code owner for patch-level dependency bumps, two approvals including security for anything that touches IAM.
What changed
A Merge rules page under Settings, with one row per fix type.
Rules are enforced in your code host through branch protection, so Quorum cannot skip them.
Every change to a rule needs two approvals from your security team and is logged.
More releases
Version 2.13
Reachability for Python services
Quorum now traces calls from Flask, Django and FastAPI routes to vulnerable packages.
Version 2.12
Quiet hours
Fixes found overnight open as drafts and post one summary in the morning.
Version 2.11
Azure storage and network checks
Storage accounts with public blob access and open network security groups.
Run a free scan on one repo
Connect one repo and one cloud account with read-only access. You get the findings and the first fix pull requests within a day, and you keep them either way.