Current intelligence source
Manage OSV data with full or incremental sync, checkpoints, retries, and item-level failure records. Synchronization requires controlled HTTPS egress to the official OSV distribution area on storage.googleapis.com.
Smart Kubaba · Intelligence Management
Match OSV data with CycloneDX SBOMs, components, environments, and project ownership, then bring verified finding and remediation context into AI-assisted development.

Outcome
Manage OSV data with full or incremental sync, checkpoints, retries, and item-level failure records. Synchronization requires controlled HTTPS egress to the official OSV distribution area on storage.googleapis.com.
Connect components, dependency edges, and findings to their CycloneDX source by project and environment.
Filter scans through central environment records and reevaluate completed scans manually or on a schedule against current intelligence and policy.
Use read-only HTTP MCP tools to discover accessible organizations and projects, then provide severity, CVSS, and verified fixed-version context to an AI development client.
Verified scope
Full synchronization downloads the official all.zip archive; incremental synchronization uses modified_id.csv and changed advisory JSON objects over controlled HTTPS egress.
Vulnerability DataComponent, dependency-edge, and finding generation by organization, project, and environment.
SBOM AnalysisPaged scan list, detail, separate raw-SBOM permission, and immutable evaluation records.
TraceabilitySeverity rules and PASS/WARN/BLOCK outcomes at organization, project, or repository scope.
Policy DecisionScoped exceptions with reason, reference, and expiry, backed by background tasks and audit records.
Exception ManagementSubmit SBOMs, query status, and integrate CI/CD decisions with scoped API tokens.
AutomationAn opt-in, read-only Streamable HTTP surface for organization/project discovery, open-vulnerability listing, and AI-oriented remediation plans.
AI IntegrationImmutable environment keys, lifecycle controls, environment-scoped policy, filtering, and scheduled bulk reevaluation.
Environment ManagementA CycloneDX document is evaluated with current intelligence and scoped policy to produce a traceable result.
Synchronize OSV advisory data in full or incrementally from the official storage.googleapis.com distribution area.
Store the CycloneDX document in its project and environment context.
Map packages and dependency relationships into the shared model.
Compare findings with the applicable policy rules.
Keep the result and later reevaluations in immutable history.
Enterprise
Every scan belongs to an organization and project; access, policy, and risk acceptance follow the same ownership model.
Technical evaluation
Let’s review your formats, deployment, and security policies together.