Current intelligence source
Manage OSV data with full or incremental sync, checkpoints, retries, and item-level failure records.
Smart Kubaba · Intelligence Management
Match OSV data with CycloneDX SBOMs, components, and project ownership.

Outcome
Manage OSV data with full or incremental sync, checkpoints, retries, and item-level failure records.
Connect components, dependency edges, and findings to their CycloneDX source by project and environment.
Preserve policy evaluation, reevaluation, and risk-acceptance history independently of later changes.
Verified scope
Managed sources, full/incremental sync, leases, checkpoints, progress, retry, and failure details.
Vulnerability DataComponent, dependency-edge, and finding generation by organization, project, and environment.
SBOM AnalysisPaged scan list, detail, separate raw-SBOM permission, and immutable evaluation records.
TraceabilitySeverity rules and PASS/WARN/BLOCK outcomes at organization, project, or repository scope.
Policy DecisionScoped exceptions with reason, reference, and expiry, backed by background tasks and audit records.
Exception ManagementSubmit SBOMs, query status, and integrate CI/CD decisions with scoped API tokens.
AutomationA CycloneDX document is evaluated with current intelligence and scoped policy to produce a traceable result.
Synchronize OSV advisory data in full or incrementally.
Store the CycloneDX document in its project and environment context.
Map packages and dependency relationships into the shared model.
Compare findings with the applicable policy rules.
Keep the result and later reevaluations in immutable history.
Enterprise
Every scan belongs to an organization and project; access, policy, and risk acceptance follow the same ownership model.
Technical evaluation
Let’s review your formats, deployment, and security policies together.