Lovable adds Wiz security scanning for connected workspaces
Wiz findings on dependencies, secrets and config now show alongside Lovable's own checks in the Security view.
Wiz security scanning is now built into Lovable. When a workspace connects its Wiz account, Wiz runs automatically alongside Lovable's existing checks (dependency auditing, code security review, RLS analysis, and database configuration checks), and findings show up in the Security view with a Wiz badge.
Wiz adds software composition analysis across the full dependency tree, sensitive data and secrets detection, and environment configuration scanning, checked against Wiz's vulnerability database and the CI/CD policies a security team has already set up in Wiz. A flagged dependency, for example, shows severity, the affected package, the fixed version, and remediation steps, and can be fixed and rescanned without leaving Lovable. Results also flow back into Wiz's own Code and Build scans page, so security teams see Lovable-built apps alongside everything else they monitor in Wiz.
The integration is available now for organizations already using Wiz; connecting a workspace is described in Lovable's announcement.

