OHRisk is a local command-line tool for assessing open-source license risk in dependencies before a pull request ships. It evaluates dependencies under SaaS or distributed-app usage profiles and labels findings low, review, high, or unknown. Inputs include dependency information from ecosystems such as npm, Rust, Go, Python, Java, .NET, Ruby, and PHP, as well as CycloneDX and SPDX software bills of materials. It can use local package evidence and selected remote evidence sources, with checksum and identity validation described for supported ecosystems. Reports are available in terminal, JSON, HTML, Markdown, SARIF 2.1.0, and CycloneDX 1.5 JSON formats. A bundled GitHub Actions composite action supports scan, ci, and diff commands, with documented SARIF upload to GitHub code scanning. Local waiver files can keep waived findings visible while preventing them from triggering CI threshold failures. OHRisk is an MIT-licensed npm package, also runnable through pnpm, Yarn, or Bun commands; its packaged CLI requires Node.js 24.0.0 or later. It is a risk aid, not a substitute for legal review, and some dependency sources and graph types are not yet scanned. The free plan is 0.00 USD per free.
Who it is for
OHRisk suits development teams assessing dependency-license risk in SaaS or distributed applications, especially teams using GitHub Actions. It can help organize review, but does not replace legal review.
What is good
- Supports many dependency ecosystems and SBOM formats
- Generates SARIF and CycloneDX reports
- GitHub Actions support includes scan, ci, and diff
- Waived findings remain visible in reports
What to know first
- Requires Node.js 24.0.0 or later
- Some dependency sources and graph types are not scanned
- Does not replace legal review
Verdict
OHRisk offers multiple report formats and CI workflows for license-risk review, including visible waivers. Its documented coverage gaps and legal-review caveat matter when interpreting its findings.
OHRisk plans and pricing
All plansCompared on open source license compliance software
- Free plan
- Yes
- Policy enforcement
- both
- Obligation tracking
- Yes
- Attribution reports
- Yes
- SBOM import formats
- CycloneDX JSON/XML; SPDX JSON/RDF; SPDX tag-value
- Deployment options
- on-premise
- Source scan methods
- multiple

