Enterprise SCA Platform

Know Every Vulnerability
in Your Open Source Stack

OsWL continuously scans your dependencies for CVEs, license obligations, and transitive risks — giving security and compliance teams complete SBOM visibility from a single self-hosted platform.

Multi-source
GHSA · OSV Advisories
9
Package Ecosystems
On-demand
deps.dev Enrichment
CVSS 3.x
Scoring Supported
Git-native
GitHub · GitLab · Bitbucket

End-to-End Software
Composition Analysis

From dependency ingestion to remediation, OsWL covers the full SCA lifecycle with enterprise-grade accuracy and auditability.

CVE Vulnerability Tracking

On-demand enrichment from deps.dev and OSV. Every component is cross-referenced against CVSS 3.x scores and patch availability, and a reminder banner surfaces when a deferred component's grace period expires.

deps.dev · OSV · GHSA
License Risk Management

Automatic SPDX classification of OSS licenses — copyleft, permissive, proprietary — with obligation rules, conflict detection, and NOTICE / SPDX SBOM export per scan.

GPL · LGPL · Apache · MIT · AGPL · MPL
Risk Trend Analysis

Track your security posture across scans. Visualize critical, high, medium, and low severity trends over time, with optional AI-generated deviation insights when an LLM provider is configured.

Version-over-version delta
Transitive Dependency Traversal

Uncover vulnerabilities hidden deep in your dependency graph. DependencyPath analysis traces both direct and transitive exposure across every supported manifest.

Maven · npm · PyPI · Go · Cargo · NuGet · RubyGems · Composer · Conan
Git-Native Repository Integration

Connect GitHub, GitLab, or Bitbucket via Personal Access Token. Quick Import queues bulk repository imports with a cancel button for jobs still running, and every scan keeps branch-aware snapshots and per-project history out of the box.

GitHub · GitLab · Bitbucket
CLI & CI/CD Pipeline Scanning

Integrate OsWL into any build pipeline with a single CLI command. Only parsed manifest metadata is uploaded — no source code leaves your build host. Bearer-token API keys per project or organization-wide.

Manifest-only upload
CycloneDX SBOM & VEX

Export a CycloneDX 1.6 SBOM, a VEX document carrying your triage decisions, or a SARIF report for code-scanning dashboards. Import third-party CycloneDX files to scan components you don’t build yourself.

CycloneDX 1.6 · VEX · SARIF 2.1.0
Policy Gates for Pull Requests

Define severity, license, and KEV thresholds per project, then let the gate pass or fail each scan. Results publish back to GitHub as a check run and PR comment, new findings are compared against a baseline so existing debt never blocks a merge, and any finding can be escalated to a linked Jira issue.

Baseline diff · GitHub check run
Organization Dashboard

One view across every project: KEV-listed and actively exploited CVEs first, EPSS exploit probability for ranking the rest, license warnings, and an audit-log export for your SIEM.

CISA KEV · EPSS · SIEM export
Embedded, Offline AI Insights

A built-in llama.cpp sidecar starts and stops from Settings, running Qwen3 1.7B Q4_K_M locally (Gemma 3 1B on low-spec hardware) — CPU-only, no API key, and nothing leaves the host. Insights honor your chosen reasoning effort and are tracked in the same usage log as every cloud provider.

llama.cpp · CPU-only · Zero internet
Air-Gapped & Offline-Ready

Import versioned OSV, deps.dev, EPSS, and KEV snapshot bundles — checksummed and provenance-stamped — to keep vulnerability intelligence current with zero outbound internet access. A wanted-list export tells you exactly which components the next bundle needs to cover, and every finding shows its data-as-of date.

Checksum · Provenance · Wanted-list export
One-Click Remediation PRs

Bump a vulnerable dependency straight from the Security Center — OsWL opens a version-bump PR or MR against GitHub, GitLab, or Bitbucket, with reviewers and a change summary attached. Run it in batch to open one PR per patchable component across an entire scan in a single action.

GitHub · GitLab · Bitbucket · Batch upgrade
Supply-Chain Attack Detection

Every resolved package name is screened for typosquatting — edit-distance and confusable-character matching against a per-ecosystem popular-package list — plus lightweight dependency-confusion signals like internal-looking names resolved from a public registry. Flagged packages surface as a verify-origin warning, never a silent block.

Typosquat detection · Dependency confusion
Enterprise SSO via OIDC

Sign in through Okta, Entra ID, or any OpenID Connect provider — SSO activates automatically once an OIDC client is configured. Logins skip the email OTP step since the identity provider already authenticated the user, while every existing role and permission rule still applies.

Okta · Entra ID · Any OIDC provider

Built for Security &
Compliance Teams

Every screen is engineered for actionability — from CVE triage to remediation tracking, no context switching required.

OsWL Security Center — CVE triage with CVSS scores
OsWL Projects Dashboard — multi-project risk overview
OsWL License Analysis — copyleft and compliance risk tracking
OsWL Risk Trend — scan-over-scan security posture

Prioritize What
Actually Matters

OsWL surfaces exploitable, patchable vulnerabilities first. CVSS scores, exploit maturity, and fix availability are enriched automatically from deps.dev and OSV advisory feeds.

Critical & High vulnerabilities flagged with patch targets
Fix version surfaced — know if a patched release exists before triaging
Transitive exposure traced to root dependency paths
Bulk status updates — mark findings reviewed or ignored in one action
backend-api · v3.2.0 — Security Center
ComponentCVE IDCVSSSeverity
jackson-databind
2.13.4.2
CVE-2022-42003 9.8 Critical
spring-webmvc
5.3.27
CVE-2023-20861 8.6 High
commons-io
2.11.0
CVE-2024-22011 7.5 High
logback-classic
1.2.11
CVE-2023-6378 6.2 Medium
guava
31.1-jre
CVE-2023-2976 5.5 Medium
GPL-2.0-only
Copyleft · Strong
Restricted
LGPL-2.1-only
Copyleft · Weak
Caution
Apache-2.0
Permissive
Permitted
MIT
Permissive
Permitted
MPL-2.0
Copyleft · File-level
Caution
Proprietary
Commercial
Unknown

Eliminate
Compliance Blind Spots

Automatically classify every SPDX license across your dependency tree. Identify copyleft obligations, license conflicts, and components that need manual legal review before they reach production.

Restricted Copyleft licenses requiring full source disclosure
Caution Weak copyleft or dual-licensed — legal review recommended
Permitted Permissive licenses — safe for commercial use

Up and Scanning
in Minutes

OsWL integrates directly into your existing development workflow. No agents, no heavyweight setup.

01

Connect Your Repository

Add a GitHub, GitLab, or Bitbucket Personal Access Token. OsWL discovers repositories and branches and imports manifests — no source code upload required.

02

Run a Dependency Scan

OsWL parses your lock files and build manifests, resolves the transitive dependency graph, and cross-references every component against deps.dev, OSV, and your license policy.

03

Triage & Remediate

Review findings in the Security Center, filter by severity, bulk-update statuses, and track your risk posture scan-over-scan in the Risk Trend dashboard.

04

Automate in CI/CD

Gate pull requests with the OsWL CLI. Bearer-token API keys enable automated scanning in any pipeline — Jenkins, GitHub Actions, GitLab CI, or custom build servers.

Secure Your
Open Source Stack

Deploy OsWL on-premise and gain full SBOM visibility across every project, team, and dependency in your organization.

Start Now → See How It Works