Methods, systems, and computer-readable media for monitoring states of application packages deployed on a cloud-based application deployment platform. A notification service retrieves a copy of a deployed application package from the cloud-based deployment platform, and determines libraries of the application package. The notification service can then determine security vulnerabilities in the libraries, and provide notifications on the vulnerabilities of the application package to a user or developer.