Skip to content

Latest commit

 

History

5 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 

Repository files navigation

OSPulse CLI

A free, no-account CLI SBOM scanner. Point it at a local repository and it walks your dependencies, emits a CycloneDX or SPDX SBOM, and produces an exploitation-first risk read from public CISA KEV + OSV intelligence, offline-capable. Detection and drafts only; it does not make you compliant.

Part of OSPulse, dependency-drift and CRA intelligence.

Install

dotnet tool (any OS with the .NET 9 runtime):

dotnet tool install --global OSPulse.Cli

Standalone binary (no runtime required), download from the latest release:

OS Asset
Windows x64 ospulse-<version>-win-x64.zip
Linux x64 ospulse-<version>-linux-x64.tar.gz
macOS (Apple Silicon) ospulse-<version>-osx-arm64.tar.gz

Each release also ships SHA256SUMS.txt. The binaries are not yet code-signed, so macOS Gatekeeper / Windows SmartScreen may warn on first run.

Use

OSPulse scan .                       # SBOM + exploitation-first risk read for the current repo
OSPulse scan . --format json         # machine-readable risk report
OSPulse sbom . --sbom-format spdx    # SBOM only (CycloneDX 1.6 or SPDX 2.3)
OSPulse scan . --offline             # no network; use the bundled CISA KEV snapshot
OSPulse scan . --fail-on exploited   # CI gate: non-zero exit if any component is on CISA KEV

The SBOM output carries the CISA SBOM Minimum Elements, component hashes, dependency relationships, a stable content-addressed serial, supplier markers, and the lifecycle phase.

Use in GitHub Actions

Gate your pipeline on exploited dependencies. The action sets up .NET, installs the CLI, and runs a scan that fails the build when a dependency is on the CISA Known Exploited Vulnerabilities list.

name: Supply-chain scan
on: [push, pull_request]
jobs:
  ospulse:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: Fortitude-Group/ospulse-cli@v1
        with:
          fail-on: exploited   # non-zero exit if any dependency is on CISA KEV

Inputs: path (default .), fail-on (default exploited, empty to report only), format (text or json), offline (true or false), version, and dotnet-version (default 9.0.x).

What it can and can't see

A local scan sees your SBOM plus public exploitation intelligence as of its data date. It does not have OSPulse's full correlated history, compromise intelligence, or your product's EU-market context, so it never renders a formal CRA Reportable verdict, and never reports a component as "safe" when it simply has no signal. The full platform at ospulse.app adds the correlated per-release inventory, CRA conformity output (draft Declaration of Conformity + Annex VII technical docs), and CRA Article 14 reporting.

Licence

Apache-2.0.

About

OSPulse CLI — free, no-account SBOM scanner with exploitation-first risk (CISA KEV + OSV).

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors