Skip to main content

Run It Locally

There is nothing to install. The web app is plain HTML, CSS and ES modules; the CLI and MCP server run on Node.js with no dependencies.

Requirements​

SurfaceRequirement
Browser dashboardAny modern browser. Must be served over HTTP — ES modules are blocked on file://
CLINode.js 18 or newer
MCP serverNode.js 18 or newer
Build / test scriptsNode.js 18 or newer (jsdom needed only for the UI and animation suites)

Everything runs on a locked-down corporate Windows workstation without admin rights. That was a hard constraint during design, not an afterthought.

Start the dashboard​

cd oss-compliance-analyzer
python -m http.server 8080 # or: npx serve .
# open http://localhost:8080

Any static server works. Then either drag an SPDX JSON file onto the page, or use one of the built-in buttons:

  • Load demo SBOM — analyses the bundled 4.2.0 IVI sample (42 components).
  • Demo milestone diff — loads the 4.1.0 and 4.2.0 pair and shows the delta.
  • Compare with previous release… — load your own baseline SBOM.

Project layout​

oss-compliance-analyzer/
index.html dashboard shell
assets/styles.css
src/license-db.js license knowledge base + SPDX expression parser
src/spdx.js SPDX 2.x parser, dependency graph, NTIA quality checks
src/risk-engine.js copyleft classification, propagation, findings, scoring
src/diff.js milestone comparison
src/report.js compliance report, NOTICE file, supplier inquiry
src/graph.js force-directed dependency graph (SVG, no libraries)
src/app.js UI wiring
samples/sample-ivisystem.spdx.json release 4.2.0
samples/sample-ivisystem-4.1.0.spdx.json release 4.1.0 (for diff)
tools/cli.mjs headless CLI: analyze / report / notice / inquiry / diff / gate
tools/mcp-server.mjs MCP server (stdio) exposing the engine as agent tools
tools/smoke-test.mjs headless test of engine + diff + reports
tools/ui-smoke-test.mjs jsdom test of the dashboard
tools/animation-smoke-test.mjs jsdom test of the architecture walkthrough
scripts/build-static.mjs builds dist/ (deploy output, excludes tools/)

Run the test suites​

npm run smoke # engine + diff + reports, no dependencies
npm run smoke:ui # dashboard in jsdom (npm i -D jsdom, or set JSDOM_ENTRY)
npm run smoke:animation # architecture walkthrough in jsdom (needs jsdom)

All three should exit 0. See the smoke test report for what they assert.

Privacy guarantee​

Supplier SBOMs are confidential, and the design enforces that structurally rather than by policy:

  • The web app makes no network requests. The only http string in the frontend is the SVG XML namespace — this was verified by static scan.
  • All parsing and analysis happen in the reviewer's browser.
  • The CLI and MCP server operate purely on local files.
  • No telemetry, no third-party API dependency.
tip

Even though the deployment is safe on a public URL for confidentiality reasons, the tool itself is worth restricting to your organisation. Put Cloudflare Zero Trust Access (or an equivalent policy) in front of it — one application policy, a few minutes of work.

Next steps​