🔒All inputs are processed locally in your browser. Nothing is transmitted, stored, or logged. Inputs disappear when you close the tab.

OCG-Industries Showcase · Cluster ⑩ Software and Cybersecurity Supply Chain

SBOM Dependency
Provenance

Enter up to five dependency rows with a component name, version, and license, then choose how you plan to distribute the build. This tool derives a component count, flags any copyleft license that conflicts with a closed-binary release, and fingerprints the row set so the same list re-run gives the same result. A dependency set is a derivation, so a consumer can re-derive the same component graph from the same inputs and see any substitution.

Data: Regulation (EU) 2024/2847 (Cyber Resilience Act) Annex I · SPDX license identifiers

Dependencies STEP 1
ComponentVersionLicense

Leave a row blank to skip it. Only rows with a component name count.

Distribution Intent STEP 2
Closed binary distribution conflicts with a GPL-3.0 or AGPL-3.0 component
SBOM Status
Pass when the license mix is clean
Components
Rows with a component name entered
License Conflicts
Copyleft components blocking a closed binary
Detail
Component count
Unknown-license count
Copyleft count
License conflict count
Distribution intent
Component digest (mutation detector, not a cryptographic digest)
Status
Policy Mandate v2.0 · what is this?