OHRisk

Input—per 1M tokens
Output—per 1M tokens
Context—tokens
WeightsClosed

About

OHRisk is ranked #6 of 27 in open source license compliance software on Inferse. It runs on Linux, macOS, Windows. There is a free plan.

Compared on open source license compliance software

Free plan
Yesgithub.com
Policy enforcement
bothgithub.com
Obligation tracking
Yesgithub.com
Attribution reports
Yesgithub.com
SBOM import formats
CycloneDX JSON/XML; SPDX JSON/RDF; SPDX tag-valuegithub.com
Deployment options
on-premisegithub.com
Source scan methods
multiplegithub.com

Facts

Purpose
Ohrisk is a local CLI that catches open-source license risk before a pull request ships.github.com · 29 Sept 2026
Risk profiles
It evaluates dependencies under SaaS or distributed-app usage profiles and reports low, review, high, or unknown findings.github.com · 29 Sept 2026
Not legal advice
Ohrisk describes itself as a risk decision aid and says it does not replace legal review.github.com · 29 Sept 2026
Outputs
It can generate terminal, JSON, HTML, Markdown, SARIF 2.1.0, and CycloneDX 1.5 JSON reports.github.com · 29 Sept 2026
CI integration
A bundled GitHub Actions composite action supports scan, ci, and diff commands, and the guide documents SARIF upload to GitHub code scanning.github.com · 29 Sept 2026
Dependency coverage
The README lists supported dependency inputs across ecosystems including npm, Rust, Go, Python, Java, .NET, Ruby, PHP, and CycloneDX or SPDX SBOMs.github.com · 29 Sept 2026
License evidence
Ohrisk can use local package evidence and selected remote evidence sources with checksum and identity validation described for supported ecosystems.github.com · 29 Sept 2026
Waivers
Local waiver files can suppress findings from CI threshold failures while keeping waived findings visible in reports.github.com · 29 Sept 2026
Scope limitation
The README states several dependency sources and graph types are not scanned yet, including Gradle graph reconstruction and remote Terraform Registry metadata.github.com · 29 Sept 2026
Runtime
The packaged CLI runs on Node.js version 24.0.0 or later, and users do not need Bun installed.github.com · 29 Sept 2026
Install
Ohrisk is distributed as an npm package and can also be run using pnpm, Yarn, or Bun package-manager commands.github.com · 29 Sept 2026
License
The repository provides Ohrisk under the MIT License.github.com · 29 Sept 2026
Maker
The GitHub maker profile is named 0disoft (ZeroDi) and lists Republic of Korea as its location.github.com · 29 Sept 2026

Best OHRisk alternatives

See all 12

Where it ranks on Inferse

Sources