← All products

Component intelligence, from an SBOM

CodeRoot Open Source

Upload a bill of materials and every component resolves to its real source repository, enriched with maintenance, contributor, release, dependency and advisory signals, then assessed for where in the world it is actually maintained.

Self-hostableHelm or ComposeRuns locally

The shape of it

From a bill of materials to intelligence

What happens to an SBOM between upload and a dossier you can cite.

How an SBOM becomes component intelligenceA CycloneDX bill of materials is ingested, each component is resolved to its source repository, that repository is enriched with maintenance, contributor, release, dependency and advisory signals, and the result is assessed for contributor geography, concentration, watchlist countries and a citeable dossier. Components that cannot be matched unambiguously branch off to triage for a person to decide.SBOMCycloneDX inResolvecomponent to source repositoryEnrichsignals gathered per repositoryAssessrisk in contextTriageambiguous or unmatcheda person decidesnothing is guessedSignalsmaintenancecontributorsreleasesdependenciesadvisoriesOutputcontributor geographyconcentrationwatchlist countriesciteable dossier
The fork is the point. A component that cannot be matched to one repository with confidence goes to triage rather than being guessed at. It is the same rule the dossiers run on, where an unstated value reads Unknown instead of being inferred from a neighbour.

The product

What it looks like

Screens from a running instance, not mockups.

A world map shading countries by how many of the catalogue's repositories have a contributor there, with watchlisted countries outlined, above a table of repositories present and risky components per country.
Contributor geography across the catalogue, with watchlisted countries outlined and a per-country risk roll-up.
A component inventory table listing name, ecosystem, resolved repository, contributor geography with concentration badges and watchlist flags, and how each component was resolved.
Every component resolved to a repository, with concentration, watchlist flags, and how the resolution was reached.
An overview screen showing SBOMs processed, components found, repository homes resolved out of total, and how many need review.
Upload an SBOM and watch it resolve. What could not be matched goes to triage rather than being guessed.
A triage queue listing components whose source repository is ambiguous or unmatched, awaiting a decision.
Ambiguous matches queue for a human decision. An unresolved component stays unresolved.

What it answers

The operational and acquisition-grade questions that decide whether software can be trusted, sustained and governed over time.

  • What is this component and what does it enable?
  • Who controls it, who maintains it, and how resilient is that stewardship?
  • How does it change, and what has changed since the last baseline?
  • What are the security, operational and compliance risks in context?
  • How does it connect to broader ecosystems and mission-relevant stacks?

Component intelligence dossiers

A stable, citeable record for each component, maintained as a living baseline. Every major claim is evidence-backed and time-stamped, with confidence levels distinguishing verified fact from analytic judgment.

  • Identification: canonical naming, aliases, forks, registry mappings and version lines
  • Stewardship: maintainer structure, bus-factor signals, governance model, workflow maturity
  • Operational readiness: release cadence, backlog aging, maintainer churn and continuity
  • Security posture: vulnerability history, recurrence patterns, patch latency, signing and attestations
  • Supply chain exposure: transitive footprint, publish pathways, shared-maintainer concentration
  • Legal baseline: licensing, obligations, drift and notable exceptions

Where your software is actually maintained

Each resolved repository is mapped to the countries its contributors work from, then scored for concentration. Components maintained from watchlisted countries are flagged on the component itself, and the catalogue rolls up into a country view showing repositories present and risky components per country. This is the question an SBOM alone cannot answer.

Editorial standards

An analyst-led workflow with structured intake, verification and publication. Verified facts and assessments are labelled distinctly, sources and timestamps are retained for auditability, change logs record what moved and why, and the analytic language stays deliberately neutral about uncertainty.

Built for

Who this is for

  • Government agencies with mission systems and regulated environments
  • Defense and intelligence organizations, commands and program offices
  • Defense primes, integrators and major suppliers
  • Critical infrastructure: energy, utilities, telecom, transportation
  • Financial services, healthcare and life sciences with high-assurance programs
  • Enterprises with formal governance, GRC and third-party risk processes

Deployment

Where it runs

Runs
Deployable entirely on your own infrastructure
Install
Docker Compose, or Helm on Kubernetes
Stack
FastAPI service, Next.js UI, Postgres, Redis, object storage
Identity
Keycloak single sign-on in production
Formats
CycloneDX SBOM ingest