Score one component on eight weighted axes - maintenance, provenance, OSSF posture, CVEs, license, origin, AI training-data provenance, and medical-device fit. Get a go / caution / no-go verdict and a rationale you can paste into your design history file.
Reviewed by
Christian Espinosa
Founder & CEO, Blue Goat Cyber
Maintenance health
weight 15Release cadence, issue triage, maintainer count
Build provenance & signing
weight 15Is the artifact signed and tied to source?
OSSF Scorecard / security posture
weight 10Public security posture (CII/OSSF Scorecard or equivalent)
Known CVEs
weight 15Open / recent CVEs against this version
License compatibility
weight 10License vs. your distribution model
Origin & sanctions exposure
weight 10Maintainer geography and sanctions risk
AI training-data provenance (for AI/ML libs)
weight 10If this is an AI/ML model or framework
Fit for medical-device use
weight 15Does the project intend to be used in safety-critical systems?
What you'll see after you submit
Common misconceptions
Myth: License is the only third-party-component concern.
Reality: License is necessary but not sufficient. Maintainer health, signing, CVE posture, and origin all drive real supply-chain risk.
Myth: OSSF Scorecard is enough on its own.
Reality: Scorecard captures repo hygiene. It does not capture fit-for-purpose, license risk, or sanctions exposure.
References & further reading
Tracked signals that change what reviewers expect. Items move on as new ones land.
CISA adds use-after-free in Linux kernel netfilter to KEV (CVE-2026-0511)
BLE pairing bypass in widely embedded Bluetooth stack added to KEV
SLSA v1.1 published - tightened build-provenance language for regulated industries
Sigstore graduates to CNCF graduated project - keyless signing becomes the supply-chain default
Score your whole SBOM + supply-chain program.
Read SBOM Readiness scorerFind what changed release-over-release and disposition the deltas.
Read SBOM Diff & VEX DrafterFor components past end-of-support that you can't replace yet.
Read Legacy / EOS TriageOperationalize component governance across the device lifecycle.
Read FDA-compliant SBOM services