Skip to main content
Security Center watches published applications for newly disclosed CVEs. When one lands on a package your organization already ships, Superblocks tells the people who can act on it instead of waiting for someone to open the dashboard. Notifications reach two audiences over two channels: For where the findings come from and how to fix them, see CVE detection.

Who receives them

Security admins are everyone holding policies:view, the same permission that opens the org-wide Security Center. The Admin and Owner roles include it by default. They see every affected application in the organization. App creators are the single user who created the application. A creator is notified about their own applications only, and is notified whether or not they hold policies:view. Deactivated users are excluded from both audiences.

When they send

Only critical and high findings send an alert. Everything else still shows in Security Center. Inbox updates as new critical and high CVEs land on published apps. The email is one digest per day. It covers new findings since the last digest, not a repeat of yesterday.

What is included

In-app: security admins

One notification per package and advisory, listing every application currently affected.

In-app: app creators

One notification per application, listing the findings detected on that application in this pass.

Turning notifications on and off

Digest emails are enabled per organization. Contact Superblocks support to turn them on or off.

Permissions