Contextual risk visibility
Match OSV data with SBOM components, dependencies, and project ownership.
Smart Kubaba · Security Management
Bring OSV intelligence, CycloneDX SBOMs, finding history, policy, and repository-firewall decisions into one security workspace.

Outcome
Match OSV data with SBOM components, dependencies, and project ownership.
Apply PASS, WARN, or BLOCK decisions by scope and severity.
Manage risk acceptance with reason, expiry, reevaluation, and an audit trail.
Product scope
Turn OSV advisory sources into current intelligence data through full or incremental synchronization.
OSVIngest, parse, and preserve project-scoped CycloneDX documents in scan context.
SBOMReview package components, versions, and dependency relationships together with project ownership.
ComponentsManage advisory matches with severity, affected-component context, and finding history.
VulnerabilitiesRun SBOM and package scans and reevaluate results against current intelligence or policy.
ScansDefine rule order, severity, and decision behavior at organization, project, and repository scope.
PolicyProduce PASS, WARN, or BLOCK decisions for proxy package requests through applicable policy.
FirewallManage exceptions with reason, scope, expiry, and reevaluation history.
AcceptanceTrack intelligence, scan, and risk-acceptance work through durable task and operation records.
TasksPreserve policy, scan, exception, and repository decisions in an auditable history.
AuditExpose organization/project discovery, vulnerability, and remediation context to authorized AI clients through read-only tools.
MCPSecurity Management evaluates package or SBOM context against current intelligence and central policy.
Record a package request or CycloneDX SBOM in its project context.
Compare components with OSV data and applicable policy.
Keep outcomes, exceptions, and reevaluation history with an audit trail.
Smart Kubaba
Security Management shares project and authorization context with Task, Source Code, Document, and Artifact Management.
Technical evaluation
Let’s review your formats, deployment, and security policies together.