Run It Locally
There is nothing to install. The web app is plain HTML, CSS and ES modules; the CLI and MCP server run on Node.js with no dependencies.
Requirements
| Surface | Requirement |
|---|---|
| Browser dashboard | Any modern browser. Must be served over HTTP — ES modules are blocked on file:// |
| CLI | Node.js 18 or newer |
| MCP server | Node.js 18 or newer |
| Build / test scripts | Node.js 18 or newer (jsdom needed only for the UI and animation suites) |
Everything runs on a locked-down corporate Windows workstation without admin rights. That was a hard constraint during design, not an afterthought.
Start the dashboard
cd oss-compliance-analyzer
python -m http.server 8080 # or: npx serve .
# open http://localhost:8080
Any static server works. Then either drag an SPDX JSON file onto the page, or use one of the built-in buttons:
- Load demo SBOM — analyses the bundled 4.2.0 IVI sample (42 components).
- Demo milestone diff — loads the 4.1.0 and 4.2.0 pair and shows the delta.
- Compare with previous release… — load your own baseline SBOM.
Project layout
oss-compliance-analyzer/
index.html dashboard shell
assets/styles.css
src/license-db.js license knowledge base + SPDX expression parser
src/spdx.js SPDX 2.x parser, dependency graph, NTIA quality checks
src/risk-engine.js copyleft classification, propagation, findings, scoring
src/diff.js milestone comparison
src/report.js compliance report, NOTICE file, supplier inquiry
src/graph.js force-directed dependency graph (SVG, no libraries)
src/app.js UI wiring
samples/sample-ivisystem.spdx.json release 4.2.0
samples/sample-ivisystem-4.1.0.spdx.json release 4.1.0 (for diff)
tools/cli.mjs headless CLI: analyze / report / notice / inquiry / diff / gate
tools/mcp-server.mjs MCP server (stdio) exposing the engine as agent tools
tools/smoke-test.mjs headless test of engine + diff + reports
tools/ui-smoke-test.mjs jsdom test of the dashboard
tools/animation-smoke-test.mjs jsdom test of the architecture walkthrough
scripts/build-static.mjs builds dist/ (deploy output, excludes tools/)
Run the test suites
npm run smoke # engine + diff + reports, no dependencies
npm run smoke:ui # dashboard in jsdom (npm i -D jsdom, or set JSDOM_ENTRY)
npm run smoke:animation # architecture walkthrough in jsdom (needs jsdom)
All three should exit 0. See the smoke test report for
what they assert.
Privacy guarantee
Supplier SBOMs are confidential, and the design enforces that structurally rather than by policy:
- The web app makes no network requests. The only
httpstring in the frontend is the SVG XML namespace — this was verified by static scan. - All parsing and analysis happen in the reviewer's browser.
- The CLI and MCP server operate purely on local files.
- No telemetry, no third-party API dependency.
Even though the deployment is safe on a public URL for confidentiality reasons, the tool itself is worth restricting to your organisation. Put Cloudflare Zero Trust Access (or an equivalent policy) in front of it — one application policy, a few minutes of work.
Next steps
- Dashboard tour — what each panel tells you.
- CLI reference — batch analysis and CI gating.
- MCP server — expose the engine to an AI agent.