OSS Compliance Smart Analyzer
OCSA ingests SPDX 2.2/2.3 JSON Software Bills of Materials, builds the dependency graph, classifies license risk with a fixed rule set, propagates copyleft obligations along static and dynamic linkage, and emits evidence-backed findings — in the browser, from a headless CLI, or through an MCP server for AI agents.
Three properties shape everything else about the tool:
- Zero runtime dependencies, zero backend. The web app is plain HTML/JS/SVG. All parsing happens on the reviewer's machine, so a confidential supplier SBOM never leaves it.
- Deterministic by design. The same SBOM always produces the same findings, and every finding carries a rule ID, a dependency-path evidence trail, an obligation and a recommended action.
- CI-ready. A release-gate command exits non-zero on policy violations, so a bad SBOM can be blocked at supplier intake.
:::warning Status — Phase 1 prototype (v0.1.0) The prototype is complete and verified, but the license tier table has not been ratified by legal counsel. Until it is, every output is engineering triage and every CRITICAL/HIGH finding requires legal confirmation. This is milestone M-8 and the single gate between the current prototype and operational use. :::
Why it exists
A Tier-1 automotive supplier receives an SBOM for every software release — typically 40–200
components with multi-level transitive dependencies, dual licensing and custom LicenseRef-
entries. Manual review does not scale, gives inconsistent verdicts between reviewers, and leaves
no evidence trail, which is indefensible in an OEM audit.
OCSA addresses five specific gaps:
| # | Gap | What OCSA does |
|---|---|---|
| 1 | Dependency structure — and therefore copyleft reachability — is invisible in raw JSON | Force-directed graph with risk-coloured nodes and linkage-coloured edges |
| 2 | Copyleft assessment varies with individual reviewer experience | One fixed rule table, applied identically every time |
| 3 | Findings are not linked to the evidence that produced them | Every finding carries its rule ID and dependency path |
| 4 | License changes between milestones go unnoticed | Identity-based milestone diff with escalation and regression detection |
| 5 | Manual reviews cannot gate a CI pipeline or a supplier delivery | gate command with a clean exit-code contract |
The three questions it answers
- What is in this software? — component inventory, versions, suppliers, purls.
- What does it oblige us to do? — obligation checklist, source-offer list, relinking list.
- What changed since the last milestone? — added/removed components, license changes, newly introduced copyleft, regressions.
It deliberately does not decide whether something is legally acceptable, does not require a server, account or network access, and does not scan source code.
Key figures
| Metric | Value |
|---|---|
| Source code | 1 982 LOC in src/, 710 LOC in tools/ + scripts/, 301 LOC markup/CSS |
| Runtime dependencies | 0 |
| Automated assertions | 138 (35 engine + 23 UI + 80 animation) — 100 % pass |
| Manual verifications | 13 — 100 % pass |
| Defects found / closed | 21 / 21 |
| Demo SBOM | 42 components, 45 relationships, score 61/HIGH, quality 50 %, 51 findings |
| Deployment payload | dist/ 281 KB, fully static |
| Interfaces | Browser UI, headless CLI (6 commands), MCP server (9 tools) |
Where to go next
- Run it locally — no build step, one command.
- How it decides — the domain model behind every verdict.
- Animated walkthrough — eight scenes explaining the operating principles; the fastest way to introduce the tool to a stakeholder.