Skip to main content
OCSA logo

OSS Compliance Smart Analyzer

SPDX SBOM visualisation and deterministic copyleft risk assessment for automotive in-vehicle software

0
Runtime dependencies
138
Automated assertions
6 + 9
CLI commands / MCP tools
281 KB
Static deploy payload

Runs entirely in your browser

Zero runtime dependencies, zero backend. Parsing and analysis happen on the reviewer’s machine, so a confidential supplier SBOM never leaves it.

Run it locally →

Deterministic, evidence-backed verdicts

The same SBOM always produces the same findings. Every finding carries a rule ID, a dependency-path evidence trail, an obligation and a recommended action.

See the finding rules →

Copyleft that actually propagates

Strong copyleft walks up the dependency graph. Static or undeclared linkage makes the parent a derivative work; weak copyleft owes a relinking mechanism.

How it decides →

Milestone diff, not re-assessment

Identity-based comparison detects added and removed components, version bumps, license changes, newly introduced copyleft and regressions to NOASSERTION.

Dashboard tour →

CI-ready release gate

The gate exits non-zero on policy violations, so a non-conforming SBOM is rejected at supplier intake instead of at the milestone review.

CLI reference →

An agent layer that cannot overrule it

An MCP server exposes the engine as nine tools. The model may explain and draft correspondence — it can never set a risk tier.

MCP server →