Smart Kubaba · Intelligence Management

See open-source risk in context.

Match OSV data with CycloneDX SBOMs, components, environments, and project ownership, then bring verified finding and remediation context into AI-assisted development.

Smart Kubaba CycloneDX scan overview with four components
A real product screen showing components projected from a CycloneDX SBOM and scan status.

Outcome

Move from vulnerability lists to security decisions.

Current intelligence source

Manage OSV data with full or incremental sync, checkpoints, retries, and item-level failure records. Synchronization requires controlled HTTPS egress to the official OSV distribution area on storage.googleapis.com.

Contextual SBOM scanning

Connect components, dependency edges, and findings to their CycloneDX source by project and environment.

Environment-based reevaluation

Filter scans through central environment records and reevaluate completed scans manually or on a schedule against current intelligence and policy.

AI-assisted development context

Use read-only HTTP MCP tools to discover accessible organizations and projects, then provide severity, CVSS, and verified fixed-version context to an AI development client.

Verified scope

Intelligence Management scope verified in the source project

OSV ingestion

Full synchronization downloads the official all.zip archive; incremental synchronization uses modified_id.csv and changed advisory JSON objects over controlled HTTPS egress.

Vulnerability Data

CycloneDX SBOM scanning

Component, dependency-edge, and finding generation by organization, project, and environment.

SBOM Analysis

Finding and scan history

Paged scan list, detail, separate raw-SBOM permission, and immutable evaluation records.

Traceability

Central policy

Severity rules and PASS/WARN/BLOCK outcomes at organization, project, or repository scope.

Policy Decision

Risk acceptance

Scoped exceptions with reason, reference, and expiry, backed by background tasks and audit records.

Exception Management

CLI and API automation

Submit SBOMs, query status, and integrate CI/CD decisions with scoped API tokens.

Automation

MCP

An opt-in, read-only Streamable HTTP surface for organization/project discovery, open-vulnerability listing, and AI-oriented remediation plans.

AI Integration

Environment catalog

Immutable environment keys, lifecycle controls, environment-scoped policy, filtering, and scheduled bulk reevaluation.

Environment Management

How does an SBOM become a decision?

A CycloneDX document is evaluated with current intelligence and scoped policy to produce a traceable result.

  1. 01Update intelligence

    Synchronize OSV advisory data in full or incrementally from the official storage.googleapis.com distribution area.

  2. 02Receive the SBOM

    Store the CycloneDX document in its project and environment context.

  3. 03Project components

    Map packages and dependency relationships into the shared model.

  4. 04Evaluate risk

    Compare findings with the applicable policy rules.

  5. 05Preserve the decision

    Keep the result and later reevaluations in immutable history.

Enterprise

Connect risk to the right organization and project.

Every scan belongs to an organization and project; access, policy, and risk acceptance follow the same ownership model.

Enterprise

Technical evaluation

Evaluate your package flow on Smart Kubaba.

Let’s review your formats, deployment, and security policies together.