OSS Risk Radar
Supply Chain Risk Intelligence

Know your dependency risk
before it ships

OSS Risk Radar surfaces operationally fragile dependencies — scored by ML and grounded in public maintenance signals.

deps.dev enrichmentGitHub signal extractionOpenSSF ScorecardML-scored maintenance risk

43

Maintenance signals per repo

4

Risk buckets

12mo

Inactivity outlook

Start an analysis

Paste a GitHub repository URL

Analysis typically completes in 30–90 seconds.

Intake mode

Run an OSS risk read.

Each repository is scored on its own. A project's dependency inventory is expected to come from an external software-composition-analysis tool (for example the OSS Review Toolkit).

Triage signal only. Evidence stays reviewable.
What you get

End-to-end supply chain clarity

From a repository URL to a calibrated, evidence-backed risk score — in under two minutes.

Repository Risk Ranking

Score a set of repositories and rank them by predicted 12-month inactivity risk, so the most fragile ones surface first.

ML Risk Scoring

A machine-learning model trained on historical maintenance outcomes — it scores operational fragility, not just known CVEs.

Multi-source Signals

Repository health, release cadence, contributor count, OpenSSF checks, and scorecard data — unified in one view.

Regime & evidence support

Every score shows whether it used full-history or cold-start signals plus an evidence-support value, so low-signal cases stay visible.

12-month Outlook

Forward-looking maintenance score predicts packages likely to go unmaintained within the next year.

Evidence Layer

Every score is traceable to raw observed signals. No black box — full auditability for security review.