Tech riderRev. 3 Oct 2026
- 1Runs onAPI, Linux, self-hosted, Web
- 2CostsFree plan
- 3℗License analysisYes
- 4SBOM standard supportboth
- 5Deployment modelself hosted
- 6Vulnerability analysisYes
- 7Policy enforcementYes
- 8SBOM exchangeYes
8 lines stated Written from the maker's own pages: github.com, trustedoss.github.io

Overview
TRUSCA is ranked #13 of 22 in SBOM management software on Specifiction. It runs on API, Linux, Self-hosted, Web. There is a free plan.
TRUSCA plans and pricing
All plansApache-2.0 self-hosted Free No per-seat licensing · self-hosted deployment trustedoss.github.io · 3 Oct 2026
Compared on SBOM management software
- SBOM standard support
- bothgithub.com
- Deployment model
- self_hostedgithub.com
- Vulnerability analysis
- Yesgithub.com
- License analysis
- Yesgithub.com
- Policy enforcement
- Yesgithub.com
- SBOM exchange
- Yesgithub.com
Facts
- Purpose
- TRUSCA is a self-hosted software composition analysis platform for CVE tracking, license compliance, and SBOM management.trustedoss.github.io · 3 Oct 2026
- Component detection
- It uses cdxgen to detect packages across 30+ language ecosystems.trustedoss.github.io · 3 Oct 2026
- Vulnerability feeds
- Trivy matches components against NVD, OSV, GitHub Advisory, EPSS, and KEV data, with new CVEs picked up on weekly database refreshes.trustedoss.github.io · 3 Oct 2026
- SBOM
- TRUSCA exports CycloneDX in JSON or XML and SPDX in JSON or Tag-Value, and can ingest CycloneDX or SPDX SBOMs.trustedoss.github.io · 3 Oct 2026
- CI integrations
- The project documents a GitHub Action, GitLab CI template, Jenkinsfile example, REST API, and API keys; its build gate can fail on a Critical CVE or forbidden license.trustedoss.github.io · 3 Oct 2026
- License workflow
- Licenses are classified as allowed, conditional, or forbidden, with NOTICE file generation and build blocking for forbidden licenses.trustedoss.github.io · 3 Oct 2026
- Notifications and audit
- Workflow features include component approval, an append-only audit log, and notifications via email, Slack, and Teams.trustedoss.github.io · 3 Oct 2026
- Security triage
- TRUSCA provides a seven-state CycloneDX VEX triage workflow and EPSS prioritization.trustedoss.github.io · 3 Oct 2026
- Not a SAST scanner
- The documentation says TRUSCA does not analyze users’ own source code and focuses on third-party components.trustedoss.github.io · 3 Oct 2026
- Deployment
- TRUSCA is distributed for users to run themselves with Docker Compose or a Helm chart; a read-only live demo is also available.trustedoss.github.io · 3 Oct 2026
- Language support
- The UI, error messages, and documentation are available in English and Korean.trustedoss.github.io · 3 Oct 2026
- Support
- The project says it has no paid support tier or managed hosting and directs users to its community support channels.github.com · 3 Oct 2026
- Intended users
- The project describes the portal as serving engineering, legal, and security teams.trustedoss.github.io · 3 Oct 2026
Best TRUSCA alternatives
See all 20 All accessCh 01 Sonatype Nexus Repository Free planFree trialAPI from $162.50/mo7.9 All accessCh 02 sbomify Free planFree trialAPI from $159/mo7.8 All accessCh 03 Keysight Eggplant Test Free trialAndroidAPI 7.5 All accessCh 04 Interlynk Free planAPILinux Free to start7.4 All accessCh 05 Exodos Labs Free planFree trialAPI from $29/mo7.3 All accessCh 06 FOSSA Free planFree trialAPI from $168392.50/mo7.3
Where it ranks on Specifiction
Is TRUSCA yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- trustedoss.github.io/trusca/docs/intro· checked 3 Oct 2026
- trustedoss.github.io/trusca/· checked 3 Oct 2026
- github.com/trustedoss/trusca/blob/main/SUPPORT.md· checked 3 Oct 2026


