Component intelligence, from an SBOM
CodeRoot Open Source
Upload a bill of materials and every component resolves to its real source repository, enriched with maintenance, contributor, release, dependency and advisory signals, then assessed for where in the world it is actually maintained.
The shape of it
From a bill of materials to intelligence
What happens to an SBOM between upload and a dossier you can cite.
The product
What it looks like
Screens from a running instance, not mockups.




What it answers
The operational and acquisition-grade questions that decide whether software can be trusted, sustained and governed over time.
- What is this component and what does it enable?
- Who controls it, who maintains it, and how resilient is that stewardship?
- How does it change, and what has changed since the last baseline?
- What are the security, operational and compliance risks in context?
- How does it connect to broader ecosystems and mission-relevant stacks?
Component intelligence dossiers
A stable, citeable record for each component, maintained as a living baseline. Every major claim is evidence-backed and time-stamped, with confidence levels distinguishing verified fact from analytic judgment.
- Identification: canonical naming, aliases, forks, registry mappings and version lines
- Stewardship: maintainer structure, bus-factor signals, governance model, workflow maturity
- Operational readiness: release cadence, backlog aging, maintainer churn and continuity
- Security posture: vulnerability history, recurrence patterns, patch latency, signing and attestations
- Supply chain exposure: transitive footprint, publish pathways, shared-maintainer concentration
- Legal baseline: licensing, obligations, drift and notable exceptions
Where your software is actually maintained
Each resolved repository is mapped to the countries its contributors work from, then scored for concentration. Components maintained from watchlisted countries are flagged on the component itself, and the catalogue rolls up into a country view showing repositories present and risky components per country. This is the question an SBOM alone cannot answer.
Editorial standards
An analyst-led workflow with structured intake, verification and publication. Verified facts and assessments are labelled distinctly, sources and timestamps are retained for auditability, change logs record what moved and why, and the analytic language stays deliberately neutral about uncertainty.
Built for
Who this is for
- Government agencies with mission systems and regulated environments
- Defense and intelligence organizations, commands and program offices
- Defense primes, integrators and major suppliers
- Critical infrastructure: energy, utilities, telecom, transportation
- Financial services, healthcare and life sciences with high-assurance programs
- Enterprises with formal governance, GRC and third-party risk processes
Deployment
Where it runs
- Runs
- Deployable entirely on your own infrastructure
- Install
- Docker Compose, or Helm on Kubernetes
- Stack
- FastAPI service, Next.js UI, Postgres, Redis, object storage
- Identity
- Keycloak single sign-on in production
- Formats
- CycloneDX SBOM ingest
