A free, no-account CLI SBOM scanner. Point it at a local repository and it walks your dependencies, emits a CycloneDX or SPDX SBOM, and produces an exploitation-first risk read from public CISA KEV + OSV intelligence, offline-capable. Detection and drafts only; it does not make you compliant.
Part of OSPulse, dependency-drift and CRA intelligence.
dotnet tool (any OS with the .NET 9 runtime):
dotnet tool install --global OSPulse.Cli
Standalone binary (no runtime required), download from the latest release:
| OS | Asset |
|---|---|
| Windows x64 | ospulse-<version>-win-x64.zip |
| Linux x64 | ospulse-<version>-linux-x64.tar.gz |
| macOS (Apple Silicon) | ospulse-<version>-osx-arm64.tar.gz |
Each release also ships SHA256SUMS.txt. The binaries are not yet code-signed, so
macOS Gatekeeper / Windows SmartScreen may warn on first run.
OSPulse scan . # SBOM + exploitation-first risk read for the current repo
OSPulse scan . --format json # machine-readable risk report
OSPulse sbom . --sbom-format spdx # SBOM only (CycloneDX 1.6 or SPDX 2.3)
OSPulse scan . --offline # no network; use the bundled CISA KEV snapshot
OSPulse scan . --fail-on exploited # CI gate: non-zero exit if any component is on CISA KEV
The SBOM output carries the CISA SBOM Minimum Elements, component hashes, dependency relationships, a stable content-addressed serial, supplier markers, and the lifecycle phase.
Gate your pipeline on exploited dependencies. The action sets up .NET, installs the CLI, and runs a scan that fails the build when a dependency is on the CISA Known Exploited Vulnerabilities list.
name: Supply-chain scan
on: [push, pull_request]
jobs:
ospulse:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: Fortitude-Group/ospulse-cli@v1
with:
fail-on: exploited # non-zero exit if any dependency is on CISA KEVInputs: path (default .), fail-on (default exploited, empty to report only), format (text or json), offline (true or false), version, and dotnet-version (default 9.0.x).
A local scan sees your SBOM plus public exploitation intelligence as of its data date. It does not have OSPulse's full correlated history, compromise intelligence, or your product's EU-market context, so it never renders a formal CRA Reportable verdict, and never reports a component as "safe" when it simply has no signal. The full platform at ospulse.app adds the correlated per-release inventory, CRA conformity output (draft Declaration of Conformity + Annex VII technical docs), and CRA Article 14 reporting.
Apache-2.0.