DEVDEER ORCA
Scan your dependencies for vulnerabilities on every build
DEVDEER ORCA (Optimized Repository Composition Analysis) runs OWASP Dependency-Check for your Azure DevOps pipelines. Vulnerability data from the National Vulnerability Database (NVD) comes from a central mirror that DEVDEER operates in Azure. In our own pipelines, a large repository is scanned in 2 to 3 minutes instead of more than an hour.
From EUR 15 per project and pipeline per month.
- mes-connector2:41 min
- service-portal2:07 min
- warehouse-api2:55 min
- label-service2:18 min
01Problem
Why OWASP Dependency-Check is slow in Azure DevOps
Since version 9, OWASP Dependency-Check downloads vulnerability data through the NVD API, which is rate limited: 5 requests per 30 seconds without an API key, 50 with one. Microsoft-hosted build agents start every run without local data, so every pipeline downloads the data again, and several builds sharing one key can run into HTTP 403 errors.
In our own pipelines, a scan of a large repository took more than an hour this way. Free Microsoft-hosted agents cancel jobs in private projects after 60 minutes.
The scan then moves to a nightly run, a weekly schedule, or gets switched off. When Log4Shell became public in late 2021, companies first had to find out which of their applications contained Log4j. A dependency scan answers exactly that question, as long as it runs.
Under NIS2, there is also the evidence side: Article 21(2)(e) of the directive requires security in system development and maintenance, including vulnerability handling. ISO 27001 covers the same in Annex A 8.8. A disabled scan is not a control.
02How ORCA works
One NVD mirror in Azure instead of a download in every pipeline
ORCA runs entirely at DEVDEER. You don't operate any infrastructure; your pipeline simply calls the service.
ORCA separates fetching vulnerability data from scanning. That is what the NVD recommends for enterprise use: route API access through a single requester.
Data mirror
A central container fetches NVD data with an NVD API key and stores it on a file share in Azure Files. After that, it only syncs changes.
Scan jobs
Every repository has its own container job in DEVDEER's Azure environment. It starts only when your pipeline calls it and uses the mirror as the data source for OWASP Dependency-Check.
Reports
Each scan job writes its report to its own folder on the file share until your pipeline picks it up.
A run in Azure DevOps
- The pipeline starts the scan job for its repository.
- The job scans the dependencies with OWASP Dependency-Check against the mirror.
- The pipeline waits for it to finish and attaches the report to the build as an artifact.
03Result
What changes in your pipelines
Scans take minutes instead of an hour, so they can run on every build. The figures come from our own Azure DevOps pipelines.
| Without a mirror | With ORCA | |
|---|---|---|
| Scan time, large repository | more than 60 minutes | 2 to 3 minutes |
| NVD requests | in every pipeline run | centrally in the mirror |
| Many builds at once | rate limit, HTTP 403 possible | no NVD requests from the pipeline |
| 60-minute limit of free Microsoft-hosted agents | can be exceeded | well below |
Every build carries its own scan report. For audits, you can show per build which dependencies were checked and with what result.
04Fit
Who ORCA is for
ORCA fits if
- you build your software in Azure DevOps,
- you scan several repositories with OWASP Dependency-Check or want to start,
- your pipelines run on Microsoft-hosted agents,
- your team can't or won't operate additional infrastructure,
- you need to show for NIS2, ISO 27001 or TISAX that your dependencies are checked regularly.
05Pricing
What ORCA costs
You pay per project and pipeline in Azure DevOps, per month. Book a bundle of seats and the price per project and pipeline goes down.
Single
EUR 30
per project and pipeline per month
Booked individually, without a bundle.
Up to 25 seats
EUR 20
per project and pipeline per month
For up to 25 projects and pipelines.
26 seats and up
EUR 15
per project and pipeline per month
For 26 projects and pipelines or more, with no upper limit.
A bundle is a fixed number of seats: you book your projects and pipelines as one package and pay the same price for every seat.
06FAQ
Frequently asked questions about ORCA
Isn't an NVD API key enough?
It raises the limit from 5 to 50 requests per 30 seconds. The first full download still takes a long time, and several builds sharing one key can run into HTTP 403. That is why the OWASP Dependency-Check documentation calls for a caching strategy in CI environments.
Why not use pipeline caching or a self-hosted agent?
Both work for individual pipelines. Azure DevOps pipeline caching is scoped per pipeline, so each one keeps its own copy and refreshes it through the NVD. A self-hosted agent with persistent storage has to be patched, monitored and scaled. ORCA keeps one data set for all repositories, and DEVDEER operates it for you.
Does ORCA find every known vulnerability?
No. ORCA scans with OWASP Dependency-Check against NVD data. Since April 2026, the NVD only enriches part of new CVEs with product data (CPE), and Dependency-Check can't map entries without that data to a library. Whatever the NVD maps, ORCA finds on every run.
Where does ORCA run, and what happens to our source code?
ORCA runs in DEVDEER's Azure environment in the West Europe region (Netherlands). Your pipeline calls ORCA like a scanning service: the scan job clones your repository, checks the dependencies and provides the report, which your pipeline attaches to the build as an artifact. Nothing stays at DEVDEER afterwards, neither your code nor the report.
Which CI systems does ORCA support?
Azure DevOps today. The scan jobs are Azure resources and don't depend on the CI system. Connecting GitHub Actions or GitLab is technically possible but not part of the standard scope.
How is ORCA different from DELTA?
ORCA checks whether the libraries and packages your software includes have known vulnerabilities. DELTA checks your own source code and shows how findings change from one scan to the next.
Is ORCA a product of the OWASP Foundation or the NVD?
No. ORCA is a DEVDEER GmbH product that uses the open-source tool OWASP Dependency-Check and the NVD API. Neither the OWASP Foundation nor the NVD has reviewed, certified or endorsed ORCA.
OWASP® is a registered trademark of the OWASP Foundation. This product uses the NVD API but is not endorsed or certified by the NVD.
Next step
Ready to create impact?
Tell us briefly what it’s about – by email or in a non-binding conversation. We listen, ask the right questions, and show how we can help in a solution-oriented and pragmatic way.
What happens next
- 01
Describe your case
Three fields, no sign-up. Two minutes is enough.
- 02
Personal reply
Stefanie Heine gets back to you within one business day.
- 03
Non-binding first conversation
We listen, ask the right questions, and show how we can help.
- hello@devdeer.com
- +49 (0) 391 - 55 68 00 5 0
- Herderstraße 31, 39108 Magdeburg
Your contact

Stefanie Heine
Executive Assistant
0/500 characters
We respond within one business day.