XmirrorSecurity/OpenSCA-cli
OpenSCA is an open source software supply chain security solution that supports the detection of open source dependencies, vulnerabilities and license compliance with a widely noticed accuracy by the community. observed · 2026-08-28
Health v2 · maintenance only
82/100
- Activity 82
- Release rhythm 72
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: 64
- age_days: 1707
- days_rel: 110
- days_push: 110
- n_releases_24m: 6
Adoption not part of the score
1125 stars · 134 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
OpenSCA-cli is an open-source Software Composition Analysis (SCA) command-line tool that scans projects to detect third-party open-source dependencies, known vulnerabilities, and license compliance risks. It generates SBOM reports in standards like SPDX, CycloneDX, and SWID, supports many language ecosystems (Java, JavaScript, Go, Python, Rust, etc.), and integrates via CLI, IDE plugins, and CI/CD pipelines.
Use cases
- scan project dependencies for known vulnerabilities
- generate an SBOM for my repository
- check open-source license compliance of dependencies
- detect transitive dependencies in go.mod or package-lock.json
- integrate SCA scanning into CI/CD pipeline
- audit third-party components for supply chain risks
- find which dependency versions fix a CVE like log4shell
When to choose
- you need a free, open-source SCA tool with multi-language dependency parsing
- you want SBOM generation in SPDX/CycloneDX/SWID formats
- you need offline or self-hosted vulnerability scanning with configurable vulnerability databases
- you want lightweight CLI/IDE/CI integration for supply chain security
When to avoid
- you need commercial-grade support, private component repository analysis, or enterprise policy management
- you need dynamic analysis or SAST/DAST rather than dependency composition analysis
- your ecosystem is not among the supported package managers
Facets
cli-tool · maturity active
security vulnerability-scanning dependency-audit parser cli developer-tools security developer-tools legal windows cli cross-platform sca sbom software-composition-analysis supply-chain-security license-compliance cyclonedx spdx devsecops vulnerability-detection dependency-scanning devops open-source linux macos docker
4 sources
- readme: https://github.com/XmirrorSecurity/OpenSCA-cli · fetched 2026-08-28 · 7bdb46c9f03c
- homepage: https://opensca.xmirror.cn · fetched 2026-08-29 · 3ec963c5cd71
- site_page: https://opensca.xmirror.cn/docs/v1 · fetched 2026-08-29 · 985107bba98c
- site_page: https://opensca.xmirror.cn/about · fetched 2026-08-29 · 723b15008c88
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| XmirrorSecurity/OpenSCA-cli | main | 82 |
For agents
markdown · JSON · MCP: product_card(name="XmirrorSecurity/OpenSCA-cli")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem