OsWL continuously scans your dependencies for CVEs, license obligations, and transitive risks — giving security and compliance teams complete SBOM visibility from a single self-hosted platform.
Core Capabilities
From dependency ingestion to remediation, OsWL covers the full SCA lifecycle with enterprise-grade accuracy and auditability.
On-demand enrichment from deps.dev and OSV. Every component is cross-referenced against CVSS 3.x scores and patch availability, and a reminder banner surfaces when a deferred component's grace period expires.
deps.dev · OSV · GHSAAutomatic SPDX classification of OSS licenses — copyleft, permissive, proprietary — with obligation rules, conflict detection, and NOTICE / SPDX SBOM export per scan.
GPL · LGPL · Apache · MIT · AGPL · MPLTrack your security posture across scans. Visualize critical, high, medium, and low severity trends over time, with optional AI-generated deviation insights when an LLM provider is configured.
Version-over-version deltaUncover vulnerabilities hidden deep in your dependency graph. DependencyPath analysis traces both direct and transitive exposure across every supported manifest.
Maven · npm · PyPI · Go · Cargo · NuGet · RubyGems · Composer · ConanConnect GitHub, GitLab, or Bitbucket via Personal Access Token. Quick Import queues bulk repository imports with a cancel button for jobs still running, and every scan keeps branch-aware snapshots and per-project history out of the box.
GitHub · GitLab · BitbucketIntegrate OsWL into any build pipeline with a single CLI command. Only parsed manifest metadata is uploaded — no source code leaves your build host. Bearer-token API keys per project or organization-wide.
Manifest-only uploadExport a CycloneDX 1.6 SBOM, a VEX document carrying your triage decisions, or a SARIF report for code-scanning dashboards. Import third-party CycloneDX files to scan components you don’t build yourself.
CycloneDX 1.6 · VEX · SARIF 2.1.0Define severity, license, and KEV thresholds per project, then let the gate pass or fail each scan. Results publish back to GitHub as a check run and PR comment, new findings are compared against a baseline so existing debt never blocks a merge, and any finding can be escalated to a linked Jira issue.
Baseline diff · GitHub check runOne view across every project: KEV-listed and actively exploited CVEs first, EPSS exploit probability for ranking the rest, license warnings, and an audit-log export for your SIEM.
CISA KEV · EPSS · SIEM exportA built-in llama.cpp sidecar starts and stops from Settings, running Qwen3 1.7B Q4_K_M locally (Gemma 3 1B on low-spec hardware) — CPU-only, no API key, and nothing leaves the host. Insights honor your chosen reasoning effort and are tracked in the same usage log as every cloud provider.
llama.cpp · CPU-only · Zero internetImport versioned OSV, deps.dev, EPSS, and KEV snapshot bundles — checksummed and provenance-stamped — to keep vulnerability intelligence current with zero outbound internet access. A wanted-list export tells you exactly which components the next bundle needs to cover, and every finding shows its data-as-of date.
Checksum · Provenance · Wanted-list exportBump a vulnerable dependency straight from the Security Center — OsWL opens a version-bump PR or MR against GitHub, GitLab, or Bitbucket, with reviewers and a change summary attached. Run it in batch to open one PR per patchable component across an entire scan in a single action.
GitHub · GitLab · Bitbucket · Batch upgradeEvery resolved package name is screened for typosquatting — edit-distance and confusable-character matching against a per-ecosystem popular-package list — plus lightweight dependency-confusion signals like internal-looking names resolved from a public registry. Flagged packages surface as a verify-origin warning, never a silent block.
Typosquat detection · Dependency confusionSign in through Okta, Entra ID, or any OpenID Connect provider — SSO activates automatically once an OIDC client is configured. Logins skip the email OTP step since the identity provider already authenticated the user, while every existing role and permission rule still applies.
Okta · Entra ID · Any OIDC providerLive Platform
Every screen is engineered for actionability — from CVE triage to remediation tracking, no context switching required.
Vulnerability Intelligence
OsWL surfaces exploitable, patchable vulnerabilities first. CVSS scores, exploit maturity, and fix availability are enriched automatically from deps.dev and OSV advisory feeds.
| Component | CVE ID | CVSS | Severity |
|---|---|---|---|
| jackson-databind 2.13.4.2 |
CVE-2022-42003 | 9.8 | Critical |
| spring-webmvc 5.3.27 |
CVE-2023-20861 | 8.6 | High |
| commons-io 2.11.0 |
CVE-2024-22011 | 7.5 | High |
| logback-classic 1.2.11 |
CVE-2023-6378 | 6.2 | Medium |
| guava 31.1-jre |
CVE-2023-2976 | 5.5 | Medium |
License Intelligence
Automatically classify every SPDX license across your dependency tree. Identify copyleft obligations, license conflicts, and components that need manual legal review before they reach production.
Workflow
OsWL integrates directly into your existing development workflow. No agents, no heavyweight setup.
Add a GitHub, GitLab, or Bitbucket Personal Access Token. OsWL discovers repositories and branches and imports manifests — no source code upload required.
OsWL parses your lock files and build manifests, resolves the transitive dependency graph, and cross-references every component against deps.dev, OSV, and your license policy.
Review findings in the Security Center, filter by severity, bulk-update statuses, and track your risk posture scan-over-scan in the Risk Trend dashboard.
Gate pull requests with the OsWL CLI. Bearer-token API keys enable automated scanning in any pipeline — Jenkins, GitHub Actions, GitLab CI, or custom build servers.
Deploy OsWL on-premise and gain full SBOM visibility across every project, team, and dependency in your organization.