OHRisk
- Android app
- Not listed
- Free plan
- Yes
- Runs on
- Linux, Mac, Windows

Summary
OHRisk is a free local command-line tool for assessing open-source license risk in software dependencies before changes reach a pull request. It evaluates dependencies under SaaS or distributed-app usage profiles and labels findings low, review, high, or unknown. Inputs include dependency information from ecosystems such as npm, Rust, Go, Python, Java, .NET, Ruby, and PHP, as well as CycloneDX and SPDX software bills of materials. It can draw on local package evidence and selected remote evidence sources, with checksum and identity validation for supported ecosystems. Reports are available in terminal, JSON, HTML, Markdown, SARIF 2.1.0, and CycloneDX 1.5 JSON formats. A bundled GitHub Actions composite action supports scan, ci, and diff commands, with documented SARIF upload to GitHub code scanning. Local waiver files can keep waived findings visible while preventing them from triggering CI threshold failures. OHRisk is an MIT-licensed npm package, also runnable through pnpm, Yarn, or Bun commands; its packaged CLI requires Node.js 24.0.0 or later. It is a risk aid, not a substitute for legal review, and some dependency sources and graph types are not yet scanned.
Who it is for
OHRisk suits developers and teams who want license-risk findings in local workflows or GitHub Actions across its supported dependency inputs. It is less suited to projects relying on dependency sources or graph types it does not yet scan.
What is good
- Free MIT-licensed npm package.
- Supports SaaS and distributed-app risk profiles.
- Generates six report formats.
- GitHub Actions supports scan, ci, and diff.
- Waivers remain visible in reports.
What to know first
- Requires Node.js 24.0.0 or later.
- Some dependency sources and graph types are not scanned.
- Does not replace legal review.
Everything Xiaomi review
OHRisk: the full review
OHRisk offers several report formats and CI support for teams checking dependency-license risk. Check its documented scan limitations and treat results as decision support rather than legal review.
Overview
OHRisk is a local command-line tool for assessing open-source license risk in project dependencies. It suits teams that want to add license checks to development workflows without sending their scan to a hosted service. Its configurable usage profiles and CI support are useful, but scan gaps mean it should not be treated as a complete inventory.
Key features
OHRisk evaluates dependencies against SaaS or distributed-app usage profiles and assigns findings a low, review, high, or unknown rating. That gives teams a way to prioritize follow-up, rather than treating every detected license as equally risky. OHRisk describes the output as decision support, not legal advice; consequential licensing decisions still call for legal review.
It accepts dependency inputs from a range of ecosystems, including npm, Rust, Go, Python, Java, .NET, Ruby, and PHP, as well as CycloneDX and SPDX SBOMs. It can use local package evidence and selected remote sources, with checksum and identity validation described for supported ecosystems. Local waiver files can prevent findings from failing CI thresholds while leaving those findings visible in reports, a practical balance between exceptions and traceability.
Reports are available in terminal, JSON, HTML, Markdown, SARIF 2.1.0, and CycloneDX 1.5 JSON formats. The range serves both people reviewing results and automated pipelines; SARIF upload to GitHub code scanning is documented. A bundled GitHub Actions composite action supports scan, ci, and diff commands.
Coverage has meaningful boundaries: some dependency sources and graph types are not scanned yet, including Gradle graph reconstruction and remote Terraform Registry metadata. Teams relying on those inputs should not assume OHRisk provides a complete dependency picture. The packaged CLI requires Node.js 24.0.0 or later, though Bun itself is not required. Installation is through npm, with pnpm, Yarn, and Bun package-manager commands also supported.
Pricing
OHRisk is free: the Ohrisk plan costs 0.00 USD per free and is open-source under the MIT License. There is no free trial because the plan is free. That makes it a straightforward option for teams comfortable operating a CLI; there are no paid tiers or seat-based plan choices to weigh.
Platforms
OHRisk supports Linux, macOS, and Windows. It is an on-premise CLI rather than a hosted web service, which fits teams that want scans run in their own development or CI environment. The Node.js 24.0.0-or-later runtime requirement is an operational consideration across those platforms.
Who it's for
OHRisk is best suited to development teams that want dependency-license risk checks in local workflows or GitHub Actions, need machine-readable reports, and can assess findings against their own policies. Its multiple scan methods, obligation tracking, and attribution reports add useful compliance context. It is a poorer fit when required dependency sources fall outside its scan coverage or when an organization needs a substitute for legal judgment.
Pros and cons
- Pros: Several report formats, including SARIF and CycloneDX JSON, make findings usable in both review and automation workflows.
- Pros: CI commands and visible waivers allow teams to enforce thresholds while retaining a record of exceptions.
- Pros: Free, MIT-licensed distribution avoids a paid-plan barrier for teams able to run a CLI.
- Cons: Unscanned sources and graph types, including Gradle graph reconstruction and remote Terraform Registry metadata, can leave gaps in coverage.
- Cons: The packaged CLI requires Node.js 24.0.0 or later, which teams must account for in their environment.
- Cons: Risk ratings are decision support, not legal advice, so they cannot replace legal review.
Alternatives
For a broader set of open-source license compliance tools, browse Open Source License Compliance Software.
- FOSSology is another free open-source license compliance toolkit, with API, desktop, self-hosted, and web platform options; consider it if those deployment choices matter more than OHRisk's local CLI workflow.
- ScanCode Toolkit is a free code-scanning tool available for API, desktop, and self-hosted use; it may suit teams seeking those forms of deployment.
- Apache Flink CDC is free and runs on Linux, macOS, Windows, and self-hosted environments; its released JARs and connectors are under Apache License 2.0.
- licscan is a free standalone CLI at $0 per scan under Apache 2.0, making it another option for teams looking for a no-cost command-line tool.
- SourceTrust offers a free tier for eligible public GitHub repositories under fair-use limits and with attribution, plus a 29.00 USD per month per-project plan; choose it if a web service is preferable to a local CLI.
- DeepFilterNet is free and open source under MIT or Apache-2.0, but its stated platforms alone do not establish it as a license-compliance alternative.
- Double Open Compliance offers a free SaaS tier and API, self-hosted, and web platforms; consider it if those deployment options are a priority.
- FOSSA has a free tier and free trial, with API, Linux, self-hosted, and web platforms; its free plan is capped at 5 projects, 10 contributing developers, 1 release group, and 5 dependency levels for scans.
Verdict
Choose OHRisk if your team wants a free, local CLI for adding license-risk checks and multi-format reports to development or CI workflows. Its GitHub Actions support and visible waiver handling are practical strengths. Look elsewhere if your dependency graph depends on sources it does not scan, or if you need legal review rather than a risk decision aid.
OHRisk plans and pricing
All plansCompared on open source license compliance software
- Free plan
- Yesgithub.com
- Policy enforcement
- bothgithub.com
- Obligation tracking
- Yesgithub.com
- Attribution reports
- Yesgithub.com
- SBOM import formats
- CycloneDX JSON/XML; SPDX JSON/RDF; SPDX tag-valuegithub.com
- Deployment options
- on-premisegithub.com
- Source scan methods
- multiplegithub.com
Facts
- Purpose
- Ohrisk is a local CLI that catches open-source license risk before a pull request ships.github.com · 29 Sept 2026
- Risk profiles
- It evaluates dependencies under SaaS or distributed-app usage profiles and reports low, review, high, or unknown findings.github.com · 29 Sept 2026
- Not legal advice
- Ohrisk describes itself as a risk decision aid and says it does not replace legal review.github.com · 29 Sept 2026
- Outputs
- It can generate terminal, JSON, HTML, Markdown, SARIF 2.1.0, and CycloneDX 1.5 JSON reports.github.com · 29 Sept 2026
- CI integration
- A bundled GitHub Actions composite action supports scan, ci, and diff commands, and the guide documents SARIF upload to GitHub code scanning.github.com · 29 Sept 2026
- Dependency coverage
- The README lists supported dependency inputs across ecosystems including npm, Rust, Go, Python, Java, .NET, Ruby, PHP, and CycloneDX or SPDX SBOMs.github.com · 29 Sept 2026
- License evidence
- Ohrisk can use local package evidence and selected remote evidence sources with checksum and identity validation described for supported ecosystems.github.com · 29 Sept 2026
- Waivers
- Local waiver files can suppress findings from CI threshold failures while keeping waived findings visible in reports.github.com · 29 Sept 2026
- Scope limitation
- The README states several dependency sources and graph types are not scanned yet, including Gradle graph reconstruction and remote Terraform Registry metadata.github.com · 29 Sept 2026
- Runtime
- The packaged CLI runs on Node.js version 24.0.0 or later, and users do not need Bun installed.github.com · 29 Sept 2026
- Install
- Ohrisk is distributed as an npm package and can also be run using pnpm, Yarn, or Bun package-manager commands.github.com · 29 Sept 2026
- License
- The repository provides Ohrisk under the MIT License.github.com · 29 Sept 2026
- Maker
- The GitHub maker profile is named 0disoft (ZeroDi) and lists Republic of Korea as its location.github.com · 29 Sept 2026
Best OHRisk alternatives
See all 20Where it ranks on Everything Xiaomi
Is OHRisk yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- github.com/0disoft/ohrisk· checked 29 Sept 2026
- github.com/0disoft/ohrisk/blob/main/docs/github-ac· checked 29 Sept 2026
- github.com/0disoft/ohrisk/blob/main/LICENSE· checked 29 Sept 2026
- github.com/0disoft· checked 29 Sept 2026

