oss-review-toolkit/ort

A suite of tools to automate software compliance checks.

View on GitHub ↗Jump to charts ↓

Summary Information

Updated 29 minutes ago
Added to GitGenius on November 17th, 2025
Created on October 19th, 2017
Open Issues & Pull Requests: 325 (+0)
Number of forks: 391
Total Stargazers: 2,073 (+0)
Total Subscribers: 36 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 21.5 days
Mean response time: 418.5 days
90th percentile: 1368.7 days
Tracked items: 636

How this project is maintained

Around half of the issues opened in the past year never receive a reply. Only 27% of open issues come from outside the core team — the tracker reads mainly as internal planning. Work labelled "to triage" is answered fastest, typically in under an hour, while "scanner" waits about 13 months. 66% of tracked open issues have had no activity in three months, so the open count overstates what is actively being worked. Only 3% of issues opened in the past year have been closed.

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 271
New in 7 days: 1
Closed in 7 days: 1
Avg open age: 894 days
Stale 30+ days: 256
Stale 90+ days: 237

Recent activity

Opened in 7 days: 1
Closed in 7 days: 1
Comments in 7 days: 6
Events in 7 days: 13

Top labels

  • analyzer (481)
  • reporter (208)
  • scanner (200)
  • question (100)
  • needs info (89)
  • configuration (86)
  • docker (77)
  • downloader (67)

Detailed Description

ORT is a policy automation and orchestration toolkit for managing open source software dependencies and compliance.

The toolkit addresses the challenge of tracking licenses, security vulnerabilities, and policy violations across software dependencies at scale. It works by combining multiple specialized tools into a customizable pipeline: an Analyzer determines project dependencies across different package managers, a Downloader fetches source code, a Scanner detects license and copyright findings, an Advisor retrieves security vulnerability data, an Evaluator applies custom policy rules, and a Reporter generates results in formats like SBOMs, attribution documentation, and compliance reports. This modular approach lets teams automate compliance checks without being locked into specific tools or formats.

ORT suits organizations with complex dependency landscapes that need systematic compliance enforcement. It works well for projects requiring SBOM generation, license compliance verification, or policy-as-code enforcement across multiple repositories. The toolkit can be used as a library, command-line tool, or through CI integrations, making it adaptable to different workflows. Teams should expect to invest in understanding the policy evaluation layer and configuring scanners and advisors for their specific compliance needs.

The project's issue tracker is primarily driven by internal planning rather than external user demand, with most issues raised by the core team. Response times to new issues and pull requests are slow, often taking weeks or longer for initial feedback. Development activity concentrates on the Analyzer, Reporter, and Scanner components, suggesting these areas receive the most attention and refinement.