Third-Party Component Risk Scorecard
Score one component on eight weighted axes - maintenance, provenance, OSSF posture, CVEs, license, origin, AI training-data provenance, and medical-device fit. Get a go / caution / no-go verdict and a rationale you can paste into your design history file.
Reviewed by
Christian Espinosa
Founder & CEO, Blue Goat Cyber
Maintenance health
weight 15Release cadence, issue triage, maintainer count
Build provenance & signing
weight 15Is the artifact signed and tied to source?
OSSF Scorecard / security posture
weight 10Public security posture (CII/OSSF Scorecard or equivalent)
Known CVEs
weight 15Open / recent CVEs against this version
License compatibility
weight 10License vs. your distribution model
Origin & sanctions exposure
weight 10Maintainer geography and sanctions risk
AI training-data provenance (for AI/ML libs)
weight 10If this is an AI/ML model or framework
Fit for medical-device use
weight 15Does the project intend to be used in safety-critical systems?
What you'll see after you submit
Eight weighted axes → one go / caution / no-go verdict
- Covers what reviewers, procurement, and security all care about - in one artifact.
- Axes weighted by impact on safety and supply-chain risk, not equally.
- Output is paste-ready for your design history file or supplier-onboarding record.
Common misconceptions
What teams usually get wrong
-
Myth: License is the only third-party-component concern.
Reality: License is necessary but not sufficient. Maintainer health, signing, CVE posture, and origin all drive real supply-chain risk.
-
Myth: OSSF Scorecard is enough on its own.
Reality: Scorecard captures repo hygiene. It does not capture fit-for-purpose, license risk, or sanctions exposure.
References & further reading
Primary sources behind this tool
- OSSF Scorecard - Open Source Security Foundation
- SLSA - Supply-chain Levels for Software Artifacts - OpenSSF / Google
- Sigstore - Linux Foundation
- FDA Cybersecurity in Medical Devices - third-party software - FDA
Recent regulatory + supply-chain activity
Tracked signals that change what reviewers expect. Items move on as new ones land.
-
Aug 18, 2026CISA KEV
CISA adds Microsoft Internet Key Exchange (IKE) Service Extensions (CVE-2026-33824) to KEV - Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
-
Aug 11, 2026CISA KEV
CISA adds Microsoft Windows Ancillary Function Driver for WinSock (CVE-2026-68820) to KEV - Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
-
Aug 4, 2026CISA KEV
CISA adds N-able N-central (CVE-2026-18556) to KEV - N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
-
Aug 4, 2026CISA KEV
CISA adds Apache Tomcat (CVE-2026-34486) to KEV - Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
Where this fits in your supply-chain program.
SBOM Readiness scorer
Score your whole SBOM + supply-chain program.
Read SBOM Readiness scorerSBOM Diff & VEX Drafter
Find what changed release-over-release and disposition the deltas.
Read SBOM Diff & VEX DrafterLegacy / EOS Triage
For components past end-of-support that you can't replace yet.
Read Legacy / EOS TriageFDA-compliant SBOM services
Operationalize component governance across the device lifecycle.
Read FDA-compliant SBOM services