oss-review-toolkit/ort
A suite of tools to automate software compliance checks. observed · 2026-08-28
Health v2 · maintenance only
95/100
- Activity 99
- Release rhythm 86
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 5
- age_days: 3240
- days_rel: 13
- days_push: 7
- n_releases_24m: 132
Adoption not part of the score
2075 stars · 392 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
The OSS Review Toolkit (ORT) is a FOSS policy automation toolkit that analyzes project dependencies, scans licenses and copyrights, checks security vulnerabilities, and generates SBOMs (SPDX, CycloneDX) and attribution documents. It can be used as a library, CLI, or CI integration and combines tools like Analyzer, Downloader, Scanner, and Advisor into customizable pipelines.
Use cases
- generate spdx or cyclonedx sbom for my project
- automate open source license compliance checks in ci
- create attribution documents for third-party dependencies
- scan dependencies for security vulnerabilities
- check licenses and copyrights of npm and maven dependencies
- enforce foss policy as code across repositories
- archive source code of all dependencies for license compliance
When to choose
- you need automated license, copyright, and vulnerability compliance across many package managers
- you must produce SBOMs or attribution docs for regulatory or customer requirements
- you want policy-as-code enforcement in CI pipelines
When to avoid
- you only need a quick one-off license scan without pipeline setup
- you need a lightweight GUI-only tool rather than a configurable toolkit
- your project uses package managers not supported by ORT's analyzer
Facets
cli-tool · maturity active
security dependency-audit developer-tools ci-cd parser documentation developer-tools security legal jvm cli cross-platform sbom spdx cyclonedx license-compliance open-source-compliance software-composition-analysis policy-as-code kotlin automation devops docker
2 sources
- readme: https://github.com/oss-review-toolkit/ort · fetched 2026-08-28 · 7167b003f788
- homepage: https://oss-review-toolkit.org · fetched 2026-08-29 · 44136fa355b3
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| oss-review-toolkit/ort | main | 95 |
For agents
markdown · JSON · MCP: product_card(name="oss-review-toolkit/ort")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem