Chi c'è dietro DevKit Dossier
DevKit Dossier è sviluppato e gestito da DevKit Srl, società di software con sede in Italia, fondata nel 2018. Il servizio gira su infrastruttura UE a Francoforte.
Abbiamo creato DevKit Dossier perché i piccoli fabbricanti di software hanno bisogno di prove CRA senza un reparto compliance. Il prodotto è self-service per scelta: niente chiamate commerciali, niente costi di attivazione, niente vincoli. Esportate tutto in qualsiasi momento.
DevKit Dossier legge SBOM SPDX® 2.3 in formato JSON e, per quanto possibile, SPDX 3.0 JSON-LD.
Contatto: support@devkit.dev
Fonti di dati e avvisi di terze parti
I dati su vulnerabilità ed exploit in DevKit Dossier provengono da fonti pubbliche con le rispettive licenze. Mostriamo fonte e licenza accanto a ogni avviso e in ogni esportazione delle prove.
- This product uses the NVD API but is not endorsed or certified by the NVD.
- Contains vulnerability data from the GitHub Advisory Database (https://github.com/advisories), licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Each advisory links to its original record at https://github.com/advisories/. We may normalize advisories or combine them with other sources.
- Vulnerability data is aggregated via OSV.dev (https://osv.dev), which republishes advisories from many upstream databases, each under its own license. The source and license of every advisory are shown next to it and in the "Third-party data notices" section of each evidence export. Advisories from Ubuntu (Ubuntu Security Team, https://github.com/canonical/ubuntu-security-notices) and from Alpine Linux (Alpine SecDB, https://secdb.alpinelinux.org) are licensed under CC BY-SA 4.0 (https://creativecommons.org/licenses/by-sa/4.0/); any adaptations of those advisories that we share are licensed under the same license.
- Exploit probability scores come from the Exploit Prediction Scoring System (EPSS), maintained by the EPSS Special Interest Group at FIRST (https://www.first.org/epss/). Scores are generated by Empirical Security and published freely. EPSS scores are probability estimates, not guarantees.
- Known-exploited status comes from the CISA Known Exploited Vulnerabilities (KEV) Catalog (https://www.cisa.gov/known-exploited-vulnerabilities-catalog), distributed under CC0 1.0. Its use does not imply endorsement by CISA or DHS.
- CVE records are copyright The MITRE Corporation and are used under the CVE Program Terms of Use (https://www.cve.org/Legal/TermsOfUse).
I dati sulle vulnerabilità di terze parti sono forniti dai rispettivi editori "così come sono", senza garanzie di alcun tipo. DevKit Dossier vi aiuta a conservare le vostre prove documentali; non fornisce consulenza legale e non certifica la conformità.
Inventario delle licenze
L'inventario delle licenze mostra, per ogni componente, la licenza scritta dal vostro strumento SBOM e la sua forma SPDX. I dati sulle licenze provengono dal vostro SBOM; DevKit Dossier non cerca le licenze altrove. Gli identificatori seguono la SPDX License List, versione 3.29.0, pubblicata dal progetto SPDX con licenza CC0 1.0.
I contrassegni segnalano le licenze che vengono comunemente riesaminate per gli obblighi copyleft. L'elenco è curato a mano ed è riportato qui per intero (elenco contrassegni 2026-09); non è una classificazione giuridica né una consulenza legale.
Segnalate per il riesame come copyleft forte: AGPL-1.0-only, AGPL-1.0-or-later, AGPL-3.0-only, AGPL-3.0-or-later, CC-BY-SA-1.0, CC-BY-SA-2.0, CC-BY-SA-2.0-UK, CC-BY-SA-2.1-JP, CC-BY-SA-2.5, CC-BY-SA-3.0, CC-BY-SA-3.0-AT, CC-BY-SA-3.0-DE, CC-BY-SA-3.0-IGO, CC-BY-SA-4.0, CECILL-2.0, CECILL-2.1, CERN-OHL-S-2.0, copyleft-next-0.3.0, copyleft-next-0.3.1, EUPL-1.0, EUPL-1.1, EUPL-1.2, GPL-1.0-only, GPL-1.0-or-later, GPL-2.0-only, GPL-2.0-or-later, GPL-3.0-only, GPL-3.0-or-later, GPL-2.0-with-autoconf-exception, GPL-2.0-with-bison-exception, GPL-2.0-with-classpath-exception, GPL-2.0-with-font-exception, GPL-2.0-with-GCC-exception, GPL-3.0-with-autoconf-exception, GPL-3.0-with-GCC-exception, NPOSL-3.0, OSL-1.0, OSL-1.1, OSL-2.0, OSL-2.1, OSL-3.0, Parity-6.0.0, Parity-7.0.0, QPL-1.0, QPL-1.0-INRIA-2004, RPL-1.1, RPL-1.5, SimPL-2.0, Sleepycat, SSPL-1.0
Segnalate per il riesame come copyleft debole: APSL-2.0, CDDL-1.0, CDDL-1.1, CECILL-C, CERN-OHL-W-2.0, CPAL-1.0, CPL-1.0, EPL-1.0, EPL-2.0, GFDL-1.1-invariants-only, GFDL-1.1-invariants-or-later, GFDL-1.1-no-invariants-only, GFDL-1.1-no-invariants-or-later, GFDL-1.1-only, GFDL-1.1-or-later, GFDL-1.2-invariants-only, GFDL-1.2-invariants-or-later, GFDL-1.2-no-invariants-only, GFDL-1.2-no-invariants-or-later, GFDL-1.2-only, GFDL-1.2-or-later, GFDL-1.3-invariants-only, GFDL-1.3-invariants-or-later, GFDL-1.3-no-invariants-only, GFDL-1.3-no-invariants-or-later, GFDL-1.3-only, GFDL-1.3-or-later, IPL-1.0, LGPL-2.0-only, LGPL-2.0-or-later, LGPL-2.1-only, LGPL-2.1-or-later, LGPL-3.0-only, LGPL-3.0-or-later, MPL-1.0, MPL-1.1, MPL-2.0, MPL-2.0-no-copyleft-exception, MS-RL
DevKit Dossier