Third-Party Component Risk Scorecard
Score one component on eight weighted axes - maintenance, provenance, OSSF posture, CVEs, license, origin, AI training-data provenance, and medical-device fit. Get a go / caution / no-go verdict and a rationale you can paste into your design history file.
Reviewed by
Christian Espinosa
Founder & CEO, Blue Goat Cyber
Maintenance health
weight 15Release cadence, issue triage, maintainer count
Build provenance & signing
weight 15Is the artifact signed and tied to source?
OSSF Scorecard / security posture
weight 10Public security posture (CII/OSSF Scorecard or equivalent)
Known CVEs
weight 15Open / recent CVEs against this version
License compatibility
weight 10License vs. your distribution model
Origin & sanctions exposure
weight 10Maintainer geography and sanctions risk
AI training-data provenance (for AI/ML libs)
weight 10If this is an AI/ML model or framework
Fit for medical-device use
weight 15Does the project intend to be used in safety-critical systems?
What you'll see after you submit
Eight weighted axes → one go / caution / no-go verdict
- Covers what reviewers, procurement, and security all care about - in one artifact.
- Axes weighted by impact on safety and supply-chain risk, not equally.
- Output is paste-ready for your design history file or supplier-onboarding record.
Common misconceptions
What teams usually get wrong
-
Myth: License is the only third-party-component concern.
Reality: License is necessary but not sufficient. Maintainer health, signing, CVE posture, and origin all drive real supply-chain risk.
-
Myth: OSSF Scorecard is enough on its own.
Reality: Scorecard captures repo hygiene. It does not capture fit-for-purpose, license risk, or sanctions exposure.
References & further reading
Primary sources behind this tool
- OSSF Scorecard - Open Source Security Foundation
- SLSA - Supply-chain Levels for Software Artifacts - OpenSSF / Google
- Sigstore - Linux Foundation
- FDA Cybersecurity in Medical Devices - third-party software - FDA
Recent regulatory + supply-chain activity
Tracked signals that change what reviewers expect. Items move on as new ones land.
-
Jun 9, 2026CISA KEV
CISA adds Arista Extensible Operating System (CVE-2026-7473) to KEV - Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability
-
Jun 2, 2026CISA KEV
CISA adds Linux Kernel (CVE-2022-0492) to KEV - Linux Kernel Improper Authentication Vulnerability
-
Jun 2, 2026CISA KEV
CISA adds Android Framework (CVE-2025-48595) to KEV - Android Framework Integer Overflow Vulnerability
-
May 20, 2026CISA KEV
CISA adds Microsoft Windows (CVE-2008-4250) to KEV - Microsoft Windows Buffer Overflow Vulnerability
Where this fits in your supply-chain program.
SBOM Readiness scorer
Score your whole SBOM + supply-chain program.
Read SBOM Readiness scorerSBOM Diff & VEX Drafter
Find what changed release-over-release and disposition the deltas.
Read SBOM Diff & VEX DrafterLegacy / EOS Triage
For components past end-of-support that you can't replace yet.
Read Legacy / EOS TriageFDA-compliant SBOM services
Operationalize component governance across the device lifecycle.
Read FDA-compliant SBOM services