Skip to main content

Domain Concepts

OCSA is a decision-support instrument for a human reviewer, not an automated compliance authority. Every output is framed as triage that a qualified engineer — and ultimately legal counsel — confirms. Understanding these eight concepts is enough to read any result.

ConceptDefinitionWhy it matters
ComponentA package in the SBOM with a resolved effective licenseThe unit of assessment
Effective licenselicenseConcluded → licenseDeclared → licenseInfoFromFiles → NOASSERTIONSuppliers populate these inconsistently; the fallback chain is what makes real SBOMs usable
Distributed unitThe shipped artefact (executable, ECU image); an SBOM rootCopyleft attaches to the shipped work, not to a repository
Linkagestatic / dynamic / unknown / dev / optionalThe single biggest determinant of a copyleft outcome
TaintAncestor-of-copyleft markerShows reachability, which is what makes a risk real or theoretical
ObligationA concrete action: disclose source, provide relinking, include noticeThe actual deliverable of compliance work
FindingRule + severity + evidence + obligation + actionThe audit artefact
Identitypurl minus version, else lowercased nameWithout it, a version bump looks like a removal plus an addition

The mental model​

The graph view exists to make this picture instantly legible: red nodes are strong copyleft, red edges are static links, and a red ring means this is reachable from copyleft.

Effective license resolution​

Suppliers populate license fields inconsistently. Some fill only licenseDeclared, some only licenseInfoFromFiles, and a depressing number fill NOASSERTION everywhere. A tool that demanded licenseConcluded would reject most real input; a tool that ignored the distinction would lose the information about how confident the verdict is.

Recording which field was used (licenseSource) is what makes the result auditable. A finding derived from licenseInfoFromFiles is weaker evidence than one derived from licenseConcluded, and the detail panel shows which.

The final guard encodes ADR-009: a LicenseRef- whose text was supplied in hasExtractedLicensingInfos is resolved for copyleft purposes. It stays UNKNOWN tier, because a human should look at it, but it does not raise the LIC-003 blocker — otherwise every proprietary component in the BOM would produce a HIGH finding and bury the real ones.

Linkage classification​

Each dependency edge is classified from the SPDX relationship type:

SPDX relationshipLinkageDevOptional
STATIC_LINKstaticnono
DYNAMIC_LINKdynamicnono
DEPENDS_ON, CONTAINS, HAS_PREREQUISITEunknownnono
DEV_DEPENDENCY_OF, BUILD_DEPENDENCY_OF, TEST_DEPENDENCY_OFunknownyesno
OPTIONAL_DEPENDENCY_OF, PROVIDED_DEPENDENCY_OFunknownnoyes

Duplicate edges between the same pair collapse, preferring an explicit STATIC_LINK or DYNAMIC_LINK over a bare DEPENDS_ON.

:::caution The conservative default DEPENDS_ON carries no linkage information, and OCSA treats it as static. In automotive firmware, linking is overwhelmingly static; assuming dynamic would systematically under-report the most common real-world violation. Every finding raised on this path states "linkage not declared", so the supplier can correct it and the finding disappears. Over-reporting with a visible, correctable reason is the right trade for a compliance gate. :::

Identity​

identityKey(c) is the purl with the version stripped — pkg:generic/qt@6.5.3 becomes pkg:generic/qt — falling back to name:<lowercased name>.

This single detail prevents a version bump from appearing as a removal plus an addition, and it is what makes the license-change comparison possible at all. Findings are matched on rule | component | title rather than ID, because IDs embed SPDXIDs that suppliers regenerate between releases.

Next​