Smart Kubaba · Intelligence Management

See open-source risk in context.

Match OSV data with CycloneDX SBOMs, components, and project ownership.

Smart Kubaba CycloneDX scan overview with four components
A real product screen showing components projected from a CycloneDX SBOM and scan status.

Outcome

Move from vulnerability lists to security decisions.

Current intelligence source

Manage OSV data with full or incremental sync, checkpoints, retries, and item-level failure records.

Contextual SBOM scanning

Connect components, dependency edges, and findings to their CycloneDX source by project and environment.

Immutable decision history

Preserve policy evaluation, reevaluation, and risk-acceptance history independently of later changes.

Verified scope

Intelligence Management scope verified in the source project

OSV ingestion

Managed sources, full/incremental sync, leases, checkpoints, progress, retry, and failure details.

Vulnerability Data

CycloneDX SBOM scanning

Component, dependency-edge, and finding generation by organization, project, and environment.

SBOM Analysis

Finding and scan history

Paged scan list, detail, separate raw-SBOM permission, and immutable evaluation records.

Traceability

Central policy

Severity rules and PASS/WARN/BLOCK outcomes at organization, project, or repository scope.

Policy Decision

Risk acceptance

Scoped exceptions with reason, reference, and expiry, backed by background tasks and audit records.

Exception Management

CLI and API automation

Submit SBOMs, query status, and integrate CI/CD decisions with scoped API tokens.

Automation

How does an SBOM become a decision?

A CycloneDX document is evaluated with current intelligence and scoped policy to produce a traceable result.

  1. 01Update intelligence

    Synchronize OSV advisory data in full or incrementally.

  2. 02Receive the SBOM

    Store the CycloneDX document in its project and environment context.

  3. 03Project components

    Map packages and dependency relationships into the shared model.

  4. 04Evaluate risk

    Compare findings with the applicable policy rules.

  5. 05Preserve the decision

    Keep the result and later reevaluations in immutable history.

Enterprise

Connect risk to the right organization and project.

Every scan belongs to an organization and project; access, policy, and risk acceptance follow the same ownership model.

Enterprise

Technical evaluation

Evaluate your package flow on Smart Kubaba.

Let’s review your formats, deployment, and security policies together.