-
Notifications
You must be signed in to change notification settings - Fork 49
OSS Risk Calculator
Gabe Stocco edited this page Jun 4, 2021
·
1 revision
OSS Risk Calculator combines two other tools, OSS Health and OSS Characteristics, to calculate a risk score for a project. You can ignore the health aspect by passing in the --no-health
command line option, and the output will be a risk level in a range from 0 (no risk) to 1 (very high risk).
The algorithm we use could definitely be improved #150.
USAGE:
Calculate a risk metric for the given package:
oss-risk-calculator --download-directory . --format text [options] package-url...
-d, --download-directory the directory to download the package to.
-r, --external-risk (Default: 0) include additional risk in final calculation.
-f, --format (Default: text) selct the output format(text|sarifv1|sarifv2)
-o, --output-file (Default: ) send the command output to a file instead of stdout
-n, --no-health (Default: false) do not check project health
--verbose (Default: false) Verbose output
-c, --use-cache (Default: false) do not download the package if it is already present in the destination
directory.
--help Display this help screen.
--version Display version information.
The package-url specifier is described at https://github.com/package-url/purl-spec:
pkg:cargo/rand The latest version of Rand (via crates.io)
pkg:cocoapods/AFNetworking The latest version of AFNetworking (via cocoapods.org)
pkg:composer/Smarty/Smarty The latest version of Smarty (via Composer/ Packagist)
pkg:cpan/Apache-ACEProxy The latest version of Apache::ACEProxy (via cpan.org)
pkg:cran/ACNE@0.8.0 Version 0.8.0 of ACNE (via cran.r-project.org)
pkg:gem/rubytree@* All versions of RubyTree (via rubygems.org)
pkg:golang/sigs.k8s.io/yaml The latest version of sigs.k8s.io/yaml (via proxy.golang.org)
pkg:github/Microsoft/DevSkim The latest release of DevSkim (via GitHub)
pkg:hackage/a50@* All versions of a50 (via hackage.haskell.org)
pkg:maven/org.apdplat/deep-qa The latest version of org.apdplat.deep-qa (via repo1.maven.org)
pkg:npm/express The latest version of Express (via npm.org)
pkg:nuget/Newtonsoft.JSON The latest version of Newtonsoft.JSON (via nuget.org)
pkg:pypi/django@1.11.1 Version 1.11.1 fo Django (via pypi.org)
pkg:ubuntu/zerofree The latest version of zerofree from Ubuntu (via packages.ubuntu.com)
pkg:vsm/MLNET/07 The latest version of MLNET.07 (from marketplace.visualstudio.com)
pkg:url/foo@1.0?url=<URL> The direct URL <URL>