OHRisk
Local CLI for open-source license risk analysis and SBOM reporting.
At a glance
- Editor scoreNot yet scored
- PricingFree plan
- Best forLocal developers needing license gates
- Free planYes
- Paid fromNone
- Policy enforcementBoth
- Facts checked20 Sep 2026
Where it wins
- Local scanning with usage profiles for SaaS and distributed applications
- Configurable CI thresholds, waivers, and dependency-difference analysis
- CycloneDX SBOMs plus SARIF, HTML, Markdown, JSON, and terminal reports
Where it doesn't
- Verified CI integration coverage is limited to GitHub Actions
- Requires Node.js and command-line workflows
- Positioned as a risk decision aid, not legal advice
Our verdict on OHRisk
OHRisk is a free, open-source command-line tool from 0disoft for developers assessing open-source license risk before merging or shipping dependencies. It runs on Windows, macOS, and Linux, with self-hosted and on-premise deployment options. The npm package runs on Node.js and analyzes dependency manifests, lockfiles, and SBOM inputs. Usage profiles for SaaS and distributed applications help classify findings in the context of how software is used, making OHRisk a focused fit for local development teams that want license gates close to the code.
Its strongest area is the connection between local analysis and release controls. CI threshold gating lets teams set configurable fail levels, while license-risk waivers and baselines provide workflows for handling accepted exceptions. Dependency-difference analysis against a Git baseline can focus review on what changed rather than requiring every dependency to be assessed as a new decision. The GitHub Actions composite action extends this workflow into CI, and reports can be generated as terminal output, HTML, Markdown, JSON, SARIF, or CycloneDX SBOMs. Deterministic third-party notices generation adds a repeatable way to produce attribution material.
OHRisk also supports obligation tracking, attribution reports, multiple source scan methods, and SBOM imports in CycloneDX JSON/XML, SPDX JSON/RDF, and SPDX tag-value formats. That breadth suits teams that need local control and machine-readable outputs without adopting a larger hosted platform. The trade-off is ecosystem scope: the verified integration is GitHub Actions, so teams centered on other CI systems may need to adapt their workflow. OHRisk should appeal to developers who prefer an open-source, local CLI with configurable policy decisions; organizations seeking broader native integrations or legal guidance should consider a different approach.
OHRisk pricing
OHRisk fact sheet
| Free plan | Yes |
|---|---|
| Paid from | None |
| Policy enforcement | Both |
| Obligation tracking | Yes |
| Attribution reports | Yes |
| SBOM import formats | CycloneDX JSON/XML; SPDX JSON/RDF; SPDX tag-value |
| Deployment options | On-premise |
| Source scan methods | Multiple |
| Deployment | Self-hosted |
| Platforms | Windows, macOS, Linux |
| Support | Docs |
| Built for | Solo, Small business (editorial estimate) |
| Integrations | 1 integrations: GitHub Actions |
| Pricing | Free plan |
| Website | github.com |
| Facts checked | 20 Sep 2026 |
OHRisk integrations
OHRisk lists 1 integrations on its own site.
- GitHub Actions
Alternatives to OHRisk
- FOSSABroad open-source compliance coverage with free access, CI/CD controls, and SBOM workflows.5.0
- OSS Review ToolkitA flexible, self-hosted toolkit with broad ecosystem coverage and policy automation.—
- FossID WorkbenchA deep governance platform for teams managing open-source risk across the software lifecycle.—
Also listed in
Used OHRisk? Be the first to review it
The editor score above is our own research. What this page doesn't have yet is a reader's view — what you used OHRisk for, what worked and what didn't. No stars are seeded and no review is paid for; an editor reads every one before it appears.
Write a reviewTwo minutes · verified accounts only · read by an editor before it appears
Featured on iTechGuides
OHRisk is listed in our Open Source License Compliance Software directory. Add the badge to your site — it links back to this page.
<a href="https://www.itechguides.com/products/ohrisk/"><img src="https://www.itechguides.com/best/badge/ohrisk.svg" alt="Featured on iTechGuides" width="230" height="46"></a>
Reviewed by iTechGuides Editors · Editorial team · Updated Sep 2026
Advertiser disclosure: iTechGuides is reader-supported. We may earn a commission when you click some links. It never changes a score or a verdict. How we rank.

