Freedom report

Three barsScore 6.5

  • Free tierA free tier is on its own pricing page
  • Open codeNo open-source code on record
  • Runs widely3 of 6 device platforms
  • DocumentedPlans, terms and facts published

OHRisk is a local command-line tool for assessing open-source license risk in dependencies before a pull request ships. It evaluates dependencies under SaaS or distributed-app usage profiles and labels findings low, review, high, or unknown. Inputs include dependency information from ecosystems such as npm, Rust, Go, Python, Java, .NET, Ruby, and PHP, as well as CycloneDX and SPDX software bills of materials. It can use local package evidence and selected remote evidence sources, with checksum and identity validation described for supported ecosystems. Reports are available in terminal, JSON, HTML, Markdown, SARIF 2.1.0, and CycloneDX 1.5 JSON formats. A bundled GitHub Actions composite action supports scan, ci, and diff commands, with documented SARIF upload to GitHub code scanning. Local waiver files can keep waived findings visible while preventing them from triggering CI threshold failures. OHRisk is an MIT-licensed npm package, also runnable through pnpm, Yarn, or Bun commands; its packaged CLI requires Node.js 24.0.0 or later. It is a risk aid, not a substitute for legal review, and some dependency sources and graph types are not yet scanned. The free plan is 0.00 USD per free.

Who it is for

OHRisk suits development teams assessing dependency-license risk in SaaS or distributed applications, especially teams using GitHub Actions. It can help organize review, but does not replace legal review.

What is good

  • Supports many dependency ecosystems and SBOM formats
  • Generates SARIF and CycloneDX reports
  • GitHub Actions support includes scan, ci, and diff
  • Waived findings remain visible in reports

What to know first

  • Requires Node.js 24.0.0 or later
  • Some dependency sources and graph types are not scanned
  • Does not replace legal review

Verdict

OHRisk offers multiple report formats and CI workflows for license-risk review, including visible waivers. Its documented coverage gaps and legal-review caveat matter when interpreting its findings.

OHRisk plans and pricing

All plans
Ohrisk Free Open-source CLI · MIT License github.com · 29 Sept 2026

Compared on open source license compliance software

Free plan
Yes
Policy enforcement
both
Obligation tracking
Yes
Attribution reports
Yes
SBOM import formats
CycloneDX JSON/XML; SPDX JSON/RDF; SPDX tag-value
Deployment options
on-premise
Source scan methods
multiple

Best OHRisk alternatives

See all 20