This MCP server provides a comprehensive open-source software supply chain risk assessment, going beyond simple CVE scanning. It aggregates live data from 7 sources including GitHub, NVD, CISA KEV, StackExchange, Hacker News, Federal Register, and Congress.gov to generate a composite Dependency Risk Score and a machine-readable verdict. It helps AppSec teams, engineering leads, and platform engineers understand the true risk of dependencies by evaluating maintainer bus factor, community health, SBOM regulatory exposure, and active exploitation status, enabling proactive vulnerability management and informed package selection.
주요 기능
01Comprehensive CVE severity distribution with CISA KEV and ransomware detection
02Parallel execution of 7 data source actors for low-latency assessments
03Maintainer bus factor analysis with contributor Gini coefficient calculation
040 GitHub stars
05SBOM compliance readiness through real-time Federal Register and Congress.gov scanning
06Composite Dependency Risk Score (0-100) with a machine-readable verdict