Smart Kubaba · Security Management

Manage software supply-chain risk in context.

Bring OSV intelligence, CycloneDX SBOMs, finding history, policy, and repository-firewall decisions into one security workspace.

Outcome

Move from vulnerability lists to actionable security decisions.

Contextual risk visibility

Match OSV data with SBOM components, dependencies, and project ownership.

Central policy

Apply PASS, WARN, or BLOCK decisions by scope and severity.

Controlled exception

Manage risk acceptance with reason, expiry, reevaluation, and an audit trail.

Product scope

Security Management capabilities

Vulnerability sources and synchronization

Turn OSV advisory sources into current intelligence data through full or incremental synchronization.

OSV

CycloneDX SBOM analysis

Ingest, parse, and preserve project-scoped CycloneDX documents in scan context.

SBOM

Component and dependency view

Review package components, versions, and dependency relationships together with project ownership.

Components

Vulnerability and finding management

Manage advisory matches with severity, affected-component context, and finding history.

Vulnerabilities

Scanning and reevaluation

Run SBOM and package scans and reevaluate results against current intelligence or policy.

Scans

Scoped security policies

Define rule order, severity, and decision behavior at organization, project, and repository scope.

Policy

Repository Firewall

Produce PASS, WARN, or BLOCK decisions for proxy package requests through applicable policy.

Firewall

Time-bound risk acceptance

Manage exceptions with reason, scope, expiry, and reevaluation history.

Acceptance

Security tasks and evaluations

Track intelligence, scan, and risk-acceptance work through durable task and operation records.

Tasks

Audit and decision trail

Preserve policy, scan, exception, and repository decisions in an auditable history.

Audit

Read-only AI context

Expose organization/project discovery, vulnerability, and remediation context to authorized AI clients through read-only tools.

MCP

How is a security decision produced?

Security Management evaluates package or SBOM context against current intelligence and central policy.

  1. 01Receive the context

    Record a package request or CycloneDX SBOM in its project context.

  2. 02Evaluate the risk

    Compare components with OSV data and applicable policy.

  3. 03Preserve the decision

    Keep outcomes, exceptions, and reevaluation history with an audit trail.

Smart Kubaba

Apply security across the complete delivery flow.

Security Management shares project and authorization context with Task, Source Code, Document, and Artifact Management.

Technical evaluation

Evaluate your package flow on Smart Kubaba.

Let’s review your formats, deployment, and security policies together.