Skip to main content

OSS Compliance Smart Analyzer

OCSA ingests SPDX 2.2/2.3 JSON Software Bills of Materials, builds the dependency graph, classifies license risk with a fixed rule set, propagates copyleft obligations along static and dynamic linkage, and emits evidence-backed findings — in the browser, from a headless CLI, or through an MCP server for AI agents.

Three properties shape everything else about the tool:

  • Zero runtime dependencies, zero backend. The web app is plain HTML/JS/SVG. All parsing happens on the reviewer's machine, so a confidential supplier SBOM never leaves it.
  • Deterministic by design. The same SBOM always produces the same findings, and every finding carries a rule ID, a dependency-path evidence trail, an obligation and a recommended action.
  • CI-ready. A release-gate command exits non-zero on policy violations, so a bad SBOM can be blocked at supplier intake.

:::warning Status — Phase 1 prototype (v0.1.0) The prototype is complete and verified, but the license tier table has not been ratified by legal counsel. Until it is, every output is engineering triage and every CRITICAL/HIGH finding requires legal confirmation. This is milestone M-8 and the single gate between the current prototype and operational use. :::

Why it exists​

A Tier-1 automotive supplier receives an SBOM for every software release — typically 40–200 components with multi-level transitive dependencies, dual licensing and custom LicenseRef- entries. Manual review does not scale, gives inconsistent verdicts between reviewers, and leaves no evidence trail, which is indefensible in an OEM audit.

OCSA addresses five specific gaps:

#GapWhat OCSA does
1Dependency structure — and therefore copyleft reachability — is invisible in raw JSONForce-directed graph with risk-coloured nodes and linkage-coloured edges
2Copyleft assessment varies with individual reviewer experienceOne fixed rule table, applied identically every time
3Findings are not linked to the evidence that produced themEvery finding carries its rule ID and dependency path
4License changes between milestones go unnoticedIdentity-based milestone diff with escalation and regression detection
5Manual reviews cannot gate a CI pipeline or a supplier deliverygate command with a clean exit-code contract

The three questions it answers​

  1. What is in this software? — component inventory, versions, suppliers, purls.
  2. What does it oblige us to do? — obligation checklist, source-offer list, relinking list.
  3. What changed since the last milestone? — added/removed components, license changes, newly introduced copyleft, regressions.

It deliberately does not decide whether something is legally acceptable, does not require a server, account or network access, and does not scan source code.

Key figures​

MetricValue
Source code1 982 LOC in src/, 710 LOC in tools/ + scripts/, 301 LOC markup/CSS
Runtime dependencies0
Automated assertions138 (35 engine + 23 UI + 80 animation) — 100 % pass
Manual verifications13 — 100 % pass
Defects found / closed21 / 21
Demo SBOM42 components, 45 relationships, score 61/HIGH, quality 50 %, 51 findings
Deployment payloaddist/ 281 KB, fully static
InterfacesBrowser UI, headless CLI (6 commands), MCP server (9 tools)

Where to go next​