Block risky builds in CI
A composite GitHub Action, a GitLab CI template, and a worked Jenkinsfile. Critical CVEs and forbidden licenses fail the build (`exit 1`); PR / MR comments post automatically with a per-finding breakdown.
Learn more →Apache-2.0 · Self-hosted · v0.10.0
The SCA tool of the TrustedOSS initiative — vulnerabilities, license compliance, and SBOMs in one self-hosted UI. No per-seat licensing.
$ git clone https://github.com/trustedoss/trusca.git && cd trusca && docker-compose -f docker-compose.dev.yml up -dEngineering blocks bad builds. Legal closes license risk. Security runs CVE triage. All in one self-hosted UI — no per-seat licensing.
A composite GitHub Action, a GitLab CI template, and a worked Jenkinsfile. Critical CVEs and forbidden licenses fail the build (`exit 1`); PR / MR comments post automatically with a per-finding breakdown.
Learn more →Allowed / conditional / forbidden classification, declared licenses from cdxgen plus detected first-party licenses from scancode, an approval workflow for conditional components, obligation tracking, and auto-generated NOTICE files.
Learn more →Trivy-backed detection across NVD + OSV + GitHub Advisory + EPSS + KEV. 7-state CycloneDX VEX triage, EPSS prioritization (column, sort, filter, policy gate), per-finding fix versions, an append-only audit log, and an automatic re-match beat that picks up new CVEs without a manual rescan.
Learn more →A compact, information-dense UI built for engineering, legal, and security teams — risk-first, with detail drawers and inline filters throughout.


