
ort
A suite of tools to automate software compliance checks.
The Lens
By Erik Loyd, SaaS CEO and former COO/CFO of an AWS Premier Partner.
Updated Aug 2026
ORT automates the open-source license-compliance work most teams either do by hand or, more honestly, don't do at all. It's a suite, Analyzer, Scanner, Advisor, Evaluator, Reporter, and Notifier, that walks your dependency tree, identifies licenses and vulnerabilities, enforces policy, and generates the compliance reports auditors ask for. It lives under the Linux Foundation's ACT initiative and carries the OpenSSF badges to match.
This is the open source answer to Black Duck, FOSSA, and Snyk's license side, tools that bill enterprises tens of thousands a year. ORT does the core job for free, wired straight into CI.
For a team shipping software with real licensing exposure, that's a serious amount of money saved. Solo devs rarely need this; small and larger teams with compliance requirements are the real audience, and self-hosting is the point.
The catch is the setup. ORT is heavy. It's a full SCA pipeline in Kotlin and Gradle, and standing it up and tuning the policy rules is a project, not an afternoon. The commercial tools charge partly for making this easy. Budget the engineering time, or the "free" gets expensive in hours.
Free vs Self-Hosted vs Paid
fully freeFree and open source under Apache 2.0, no paid tier. It directly substitutes for commercial SCA platforms (Black Duck, FOSSA, Snyk) that run five to six figures a year. The trade is ops: expect meaningful engineering time to deploy, integrate into CI, and tune policy rules before it's producing clean reports.
Free and open source. Replaces five-figure SCA platforms if you can staff the setup.
Get tools like this every Wednesday
One featured tool, three on the radar. No fluff.
Similar Tools

Find secrets with Gitleaks 🔑

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Open source secret management platform

A vulnerability scanner for container images and filesystems

Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.

Find, verify, and analyze leaked credentials
A low score is not a verdict on quality. Young and niche tools start low by design. How we calculate scores
Trust Signals
License: Apache License 2.0
Use freely. Patent grant included.
Commercial use: ✓ Yes
About
- Owner
- OSS Review Toolkit (Organization)
- Stars
- 2,062
- Forks
- 388