A read-only health and security scanner for Cloud Foundry landscapes on SAP BTP.

Point BTP Lens at a Cloud Foundry (CF) org on SAP BTP (Business Technology Platform). With nothing more than the Space Auditor role, it inventories every app, flags stale deployments, end-of-life runtimes, outdated buildpacks and libraries, known vulnerabilities and risky configuration, and writes an offline HTML report plus JSON (JavaScript Object Notation), CSV (comma-separated values) and SARIF (Static Analysis Results Interchange Format).

Open source under Apache-2.0, free for everyone, built in public, and it runs on your machine.

Try it in five minutes

npx btp-lens

You need Node.js (the LTS, long-term support, installer) and a BTP login with the Space Auditor role, which is read-only. You do not need the cf command-line tool (CLI).

If something does not work, npx btp-lens doctor checks Node.js, network, certificates, login and the output folder and tells you what to do in one sentence each.

v0.1 is in development. Until 0.1.0 is published, run it from source with Node.js 22.12 or later.

Read-only

It sends only GET requests to the Cloud Foundry API (application programming interface).

The HTTP client refuses any method other than GET to the CF API. The only POST requests go to the OAuth token endpoint (the sign-in standard Cloud Foundry uses) and to the OSV.dev vulnerability batch API.

CF API: GET only · POST: /oauth/token, OSV.dev querybatch

Nothing leaves your machine

Requests go only to your landscape and four public lookups.

Your CF API, UAA (User Account and Authentication service) and log cache, plus api.osv.dev, endoflife.date, ui5.sap.com (version overview) and registry.npmjs.org (four @sap/* packages). There is no telemetry. Report folders and files are created readable by you only.

telemetry: none · report folders 0700 · files 0600

Least privilege

Space Auditor, a read-only role, is enough.

User names, tokens and secret values are never written into its output. When a call returns 403, the check is recorded as skipped: insufficient role and the scan continues.

minimum role: Space Auditor · 403: skipped, scan continues

One file, opens offline

See the sample report
Overview page of the sample report for the acme-prod landscape: a plain-words summary, tiles for 8 apps scanned and 0 critical or high findings, a findings-by-severity chart (1 medium, 2 low) and the three top risky apps
fig. 1 · Sample report from the synthetic acme-prod fixture landscape: 8 apps, 3 findings (1 medium, 2 low).
Formats
A single-file HTML report plus JSON, CSV and SARIF 2.1.0. The CSV output neutralizes spreadsheet formulas; the SARIF output is ready for code-scanning tools.
Offline
Fonts, themes and data are embedded. The report follows your light or dark system setting and works at phone width.
Locked down
It carries a Content Security Policy with connect-src 'none', so the browser itself refuses to let it connect anywhere, and only the scripts bundled at build time may run.
Re-run offline
btp-lens report --from <snapshot.json> re-runs every rule on a snapshot, for example after you upgrade BTP Lens.
Exit codes
0: no findings at or above --fail-on (the default, none, never fails). 1: findings met the threshold. 2: tool error.
Files
Report folders and files are created readable by you only (0700 and 0600).

Every finding has a stable rule id, a severity, the evidence that triggered it, a concrete remediation and reference links. Rules are pure functions of the collected data. They use the scan time as "now", so btp-lens report --from snapshot.json gives the same result offline.

Rules in v0.1: status, severity and the minimum Cloud Foundry role each needs
Rule idWhat it flagsStatusSeverityNeeds
APP_NO_RECENT_DEPLOYLast deploy older than 12 monthsimplementedlow / mediumSpace Auditor
RUNTIME_NODE_EOL, RUNTIME_JAVA_EOLThe runtime version is past, or within 90 days of, its end of life (EOL)planned, slice 2medium / highSpace Auditor
DEP_KNOWN_CVEA dependency in the SBOM (software bill of materials) has a known vulnerability (a CVE, a Common Vulnerabilities and Exposures entry)planned, slice 3from CVSS (Common Vulnerability Scoring System)none (local SBOM)
APP_IDLEThe app is stopped for a long time, or runs with no sign of useplanned, slice 4lowSpace Auditor
UI5_OUT_OF_MAINTENANCEThe SAPUI5 version served by the app is out of maintenanceplanned, slice 5medium / highSpace Auditor
BUILDPACK_OUTDATEDThe droplet was built with an older buildpack than the platform currently offersplannedlow / mediumSpace Auditor
STACK_DEPRECATEDThe app runs on a deprecated stackplannedmedium / highSpace Auditor
SAP_PKG_OUTDATED@sap/cds, @sap/approuter, @sap/xssec or @sap/xsenv is behind the current major versionplannedmedium / highnone (local SBOM)
ENV_SECRET_PLAINTEXTAn environment variable whose name looks like a secret is set directly on the appplannedhighSpace Developer or Space Supporter, --deep

Two severities mean the rule picks one by threshold: APP_NO_RECENT_DEPLOY is low when the current droplet is more than 365 days old and medium past 730 days; the runtime rules are medium within 90 days of end of life and high past it. For planned rules the severity logic is the design, confirmed or adjusted when the rule is implemented.

Apps are ranked by a weighted sum of their findings: critical 100, high 25, medium 5, low 1, info 0. A score of 0 means that no rule matched; it does not mean the app is safe.

Posts and guides

All posts

The first posts are in review and will appear here when they are published.

Start here

New to Cloud Foundry on SAP BTP: the tool pages in reading order, then the posts as they are published.

  1. Getting started without being a developer
  2. Permissions: which role a scan needs
  3. Privacy: where requests go and what is never kept
The full path