A read-only health and security scanner for Cloud Foundry landscapes on SAP BTP.
Point BTP Lens at a Cloud Foundry (CF) org on SAP BTP (Business Technology Platform). With nothing more than the Space Auditor role, it inventories every app, flags stale deployments, end-of-life runtimes, outdated buildpacks and libraries, known vulnerabilities and risky configuration, and writes an offline HTML report plus JSON (JavaScript Object Notation), CSV (comma-separated values) and SARIF (Static Analysis Results Interchange Format).
Open source under Apache-2.0, free for everyone, built in public, and it runs on your machine.
Try it in five minutes
npx btp-lens You need Node.js (the LTS, long-term support, installer) and a BTP login with the Space Auditor role, which is read-only. You do not need the cf command-line tool (CLI).
If something does not work, npx btp-lens doctor checks Node.js, network, certificates, login and the output folder and tells you what to do in one sentence each.
v0.1 is in development. Until 0.1.0 is published, run it from source with Node.js 22.12 or later.
Read-only, by construction
Privacy, permissions and the security reviewRead-only
It sends only GET requests to the Cloud Foundry API (application programming interface).
The HTTP client refuses any method other than GET to the CF API. The only POST requests go to the OAuth token endpoint (the sign-in standard Cloud Foundry uses) and to the OSV.dev vulnerability batch API.
CF API: GET only · POST: /oauth/token, OSV.dev querybatchNothing leaves your machine
Requests go only to your landscape and four public lookups.
Your CF API, UAA (User Account and Authentication service) and log cache, plus api.osv.dev, endoflife.date, ui5.sap.com (version overview) and registry.npmjs.org (four @sap/* packages). There is no telemetry. Report folders and files are created readable by you only.
telemetry: none · report folders 0700 · files 0600Least privilege
Space Auditor, a read-only role, is enough.
User names, tokens and secret values are never written into its output. When a call returns 403, the check is recorded as skipped: insufficient role and the scan continues.
One file, opens offline
See the sample report
- Formats
- A single-file HTML report plus JSON, CSV and SARIF 2.1.0. The CSV output neutralizes spreadsheet formulas; the SARIF output is ready for code-scanning tools.
- Offline
- Fonts, themes and data are embedded. The report follows your light or dark system setting and works at phone width.
- Locked down
- It carries a Content Security Policy with
connect-src 'none', so the browser itself refuses to let it connect anywhere, and only the scripts bundled at build time may run. - Re-run offline
btp-lens report --from <snapshot.json>re-runs every rule on a snapshot, for example after you upgrade BTP Lens.- Exit codes
- 0: no findings at or above
--fail-on(the default,none, never fails). 1: findings met the threshold. 2: tool error. - Files
- Report folders and files are created readable by you only (
0700and0600).
What it checks in v0.1
All rules, with evidence and remediationEvery finding has a stable rule id, a severity, the evidence that triggered it, a concrete remediation and reference links. Rules are pure functions of the collected data. They use the scan time as "now", so btp-lens report --from snapshot.json gives the same result offline.
| Rule id | What it flags | Status | Severity | Needs |
|---|---|---|---|---|
| APP_NO_RECENT_DEPLOY | Last deploy older than 12 months | implemented | low / medium | Space Auditor |
| RUNTIME_NODE_EOL, RUNTIME_JAVA_EOL | The runtime version is past, or within 90 days of, its end of life (EOL) | planned, slice 2 | medium / high | Space Auditor |
| DEP_KNOWN_CVE | A dependency in the SBOM (software bill of materials) has a known vulnerability (a CVE, a Common Vulnerabilities and Exposures entry) | planned, slice 3 | from CVSS (Common Vulnerability Scoring System) | none (local SBOM) |
| APP_IDLE | The app is stopped for a long time, or runs with no sign of use | planned, slice 4 | low | Space Auditor |
| UI5_OUT_OF_MAINTENANCE | The SAPUI5 version served by the app is out of maintenance | planned, slice 5 | medium / high | Space Auditor |
| BUILDPACK_OUTDATED | The droplet was built with an older buildpack than the platform currently offers | planned | low / medium | Space Auditor |
| STACK_DEPRECATED | The app runs on a deprecated stack | planned | medium / high | Space Auditor |
| SAP_PKG_OUTDATED | @sap/cds, @sap/approuter, @sap/xssec or @sap/xsenv is behind the current major version | planned | medium / high | none (local SBOM) |
| ENV_SECRET_PLAINTEXT | An environment variable whose name looks like a secret is set directly on the app | planned | high | Space Developer or Space Supporter, --deep |
Two severities mean the rule picks one by threshold: APP_NO_RECENT_DEPLOY is low when the current droplet is more than 365 days old and medium past 730 days; the runtime rules are medium within 90 days of end of life and high past it. For planned rules the severity logic is the design, confirmed or adjusted when the rule is implemented.
Apps are ranked by a weighted sum of their findings: critical 100, high 25, medium 5, low 1, info 0. A score of 0 means that no rule matched; it does not mean the app is safe.
Posts and guides
All postsThe first posts are in review and will appear here when they are published.
Start here
New to Cloud Foundry on SAP BTP: the tool pages in reading order, then the posts as they are published.
- Getting started without being a developer
- Permissions: which role a scan needs
- Privacy: where requests go and what is never kept