About DevKit Dossier
DevKit Dossier is built and operated by DevKit Srl, a software company based in Italy, founded in 2018. The service runs on EU infrastructure in Frankfurt.
We built DevKit Dossier because small software manufacturers need CRA evidence without a compliance department. The product is self-serve by design: no sales calls, no onboarding fees, no lock-in. Export everything at any time.
DevKit Dossier reads SPDX® 2.3 JSON SBOMs, and SPDX 3.0 JSON-LD on a best-effort basis.
Contact: support@devkit.dev
Data sources and third-party notices
Vulnerability and exploit data in DevKit Dossier comes from public sources under their own licenses. We show the source and license next to every advisory and in every evidence export.
- This product uses the NVD API but is not endorsed or certified by the NVD.
- Contains vulnerability data from the GitHub Advisory Database (https://github.com/advisories), licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Each advisory links to its original record at https://github.com/advisories/. We may normalize advisories or combine them with other sources.
- Vulnerability data is aggregated via OSV.dev (https://osv.dev), which republishes advisories from many upstream databases, each under its own license. The source and license of every advisory are shown next to it and in the "Third-party data notices" section of each evidence export. Advisories from Ubuntu (Ubuntu Security Team, https://github.com/canonical/ubuntu-security-notices) and from Alpine Linux (Alpine SecDB, https://secdb.alpinelinux.org) are licensed under CC BY-SA 4.0 (https://creativecommons.org/licenses/by-sa/4.0/); any adaptations of those advisories that we share are licensed under the same license.
- Exploit probability scores come from the Exploit Prediction Scoring System (EPSS), maintained by the EPSS Special Interest Group at FIRST (https://www.first.org/epss/). Scores are generated by Empirical Security and published freely. EPSS scores are probability estimates, not guarantees.
- Known-exploited status comes from the CISA Known Exploited Vulnerabilities (KEV) Catalog (https://www.cisa.gov/known-exploited-vulnerabilities-catalog), distributed under CC0 1.0. Its use does not imply endorsement by CISA or DHS.
- CVE records are copyright The MITRE Corporation and are used under the CVE Program Terms of Use (https://www.cve.org/Legal/TermsOfUse).
Third-party vulnerability data is provided by its publishers "as is", without warranty of any kind. DevKit Dossier helps you keep evidence records; it does not provide legal advice or certify compliance.
License inventory
The license inventory shows, for every component, the license your SBOM tool wrote and its SPDX form. License data comes from your own SBOM; DevKit Dossier does not look licenses up elsewhere. Identifiers follow the SPDX License List, version 3.29.0, published by the SPDX project under CC0 1.0.
Flags mark licenses commonly reviewed for copyleft obligations. The list is curated by hand and shown here in full (flag list 2026-09); it is not a legal classification and not legal advice.
Flagged for review as strong copyleft: AGPL-1.0-only, AGPL-1.0-or-later, AGPL-3.0-only, AGPL-3.0-or-later, CC-BY-SA-1.0, CC-BY-SA-2.0, CC-BY-SA-2.0-UK, CC-BY-SA-2.1-JP, CC-BY-SA-2.5, CC-BY-SA-3.0, CC-BY-SA-3.0-AT, CC-BY-SA-3.0-DE, CC-BY-SA-3.0-IGO, CC-BY-SA-4.0, CECILL-2.0, CECILL-2.1, CERN-OHL-S-2.0, copyleft-next-0.3.0, copyleft-next-0.3.1, EUPL-1.0, EUPL-1.1, EUPL-1.2, GPL-1.0-only, GPL-1.0-or-later, GPL-2.0-only, GPL-2.0-or-later, GPL-3.0-only, GPL-3.0-or-later, GPL-2.0-with-autoconf-exception, GPL-2.0-with-bison-exception, GPL-2.0-with-classpath-exception, GPL-2.0-with-font-exception, GPL-2.0-with-GCC-exception, GPL-3.0-with-autoconf-exception, GPL-3.0-with-GCC-exception, NPOSL-3.0, OSL-1.0, OSL-1.1, OSL-2.0, OSL-2.1, OSL-3.0, Parity-6.0.0, Parity-7.0.0, QPL-1.0, QPL-1.0-INRIA-2004, RPL-1.1, RPL-1.5, SimPL-2.0, Sleepycat, SSPL-1.0
Flagged for review as weak copyleft: APSL-2.0, CDDL-1.0, CDDL-1.1, CECILL-C, CERN-OHL-W-2.0, CPAL-1.0, CPL-1.0, EPL-1.0, EPL-2.0, GFDL-1.1-invariants-only, GFDL-1.1-invariants-or-later, GFDL-1.1-no-invariants-only, GFDL-1.1-no-invariants-or-later, GFDL-1.1-only, GFDL-1.1-or-later, GFDL-1.2-invariants-only, GFDL-1.2-invariants-or-later, GFDL-1.2-no-invariants-only, GFDL-1.2-no-invariants-or-later, GFDL-1.2-only, GFDL-1.2-or-later, GFDL-1.3-invariants-only, GFDL-1.3-invariants-or-later, GFDL-1.3-no-invariants-only, GFDL-1.3-no-invariants-or-later, GFDL-1.3-only, GFDL-1.3-or-later, IPL-1.0, LGPL-2.0-only, LGPL-2.0-or-later, LGPL-2.1-only, LGPL-2.1-or-later, LGPL-3.0-only, LGPL-3.0-or-later, MPL-1.0, MPL-1.1, MPL-2.0, MPL-2.0-no-copyleft-exception, MS-RL
DevKit Dossier