Skip to main content

Apache-2.0 · Self-hosted · v0.10.0

TRUSCA

The SCA tool of the TrustedOSS initiative — vulnerabilities, license compliance, and SBOMs in one self-hosted UI. No per-seat licensing.

$ git clone https://github.com/trustedoss/trusca.git && cd trusca && docker-compose -f docker-compose.dev.yml up -d
30+
languages & build systems detected (cdxgen)
NVD · OSV · GHSA · EPSS · KEV
vulnerability feeds via Trivy single engine
EN · KO
bilingual UI & documentation from day one

See it in action

A compact, information-dense UI built for engineering, legal, and security teams — risk-first, with detail drawers and inline filters throughout.

Project portfolio list with per-project scan status and inline search, filter, and sort.
Portfolio view — every project, scan status, and risk at a glance.
Vulnerability list showing CVE IDs, severity badges, CVSS, and VEX status workflow.
Vulnerabilities — severity-ranked CVEs with a VEX status workflow.
SBOM tab with download buttons for CycloneDX JSON, CycloneDX XML, SPDX JSON, and SPDX Tag-Value.
SBOM export — CycloneDX and SPDX, ready to download.