AI powered OSS Compliance Platform

We are building the future of Open Source Software compliance with AI-powered tools to make compliance accessible to everyone.

100%
Complete
14
Components
15K+
Downloads

Welcome to SEMCL.ONE

Welcome to the SEMCL.ONE Community! ......

December 04, 2025

Catching Problematic AI-Generated Code That Evades Traditional Scanners

AI transforms GPL-licensed and patented code, making it invisible to traditional scanners. Learn how transformation-resistant signatures detect contamination that evades...

December 04, 2025

Component Status

PURL to Source Ready
v1.2.4 | MIT | 1.2K+ Downloads

Downloads source code from Package URLs (npm, PyPI, Maven, etc.)

CopycatM Ready
v1.7.0 | Private Beta

Detects IP contamination in LLM-generated code through semantic pattern matching

Binary Sniffer Ready
v1.11.3 | MIT | 636 Downloads

Identifies hidden OSS components embedded in binary files

OSS License ID Library Ready
v1.7.0 | Apache-2.0 | 4.8K+ Downloads

High-performance license detection across 700+ SPDX identifiers with confidence scores

PURL to Notices Ready
v1.3.0 | MIT | 833 Downloads

Generates legal notices with licenses and copyright information

OSS Notices Ready
v1.0.2 | MIT | 463 Downloads

Simplified CLI wrapper for generating open source legal notices

UPMEX Ready
v1.6.8 | MIT | 1.3K+ Downloads

Universal package metadata extractor supporting 13 package ecosystems

Source to PURL Ready
v1.3.5 | AGPL-3.0 | 379 Downloads

Identifies package coordinates from source code using SWHIDs and multiple strategies

VulnQ Ready
v1.0.2 | Apache-2.0 | 515 Downloads

Lightweight, multi-source vulnerability query tool that consolidates security data from OSV.dev, GitHub Advisory, and NIST NVD using PURLs, CPE strings, and file hashes

OSPAC Ready
v1.2.11 | Apache-2.0 | 2.2K+ Downloads

Open Source Policy as Code - policy engine with declarative, data-driven compliance logic defined in versionable policy files

MCP-SemClone Ready
v1.6.3 | Apache-2.0 | 768 Downloads

Model Context Protocol server providing comprehensive OSS compliance and vulnerability analysis capabilities through the SEMCL.ONE toolchain

OSSBomer Ready
v2.2.2 | Apache-2.0 | 807 Downloads

Profile-driven SBOM validation, conformance and license policy for SPDX and CycloneDX, where each regulation is one YAML profile and every rule cites the clause it comes from

SUPHM Ready
v0.3.6 | AGPL-3.0 | 984 Downloads

Supply chain health metrics: analyses OSS package health, maintainer burnout and supply-chain risk

OSSVal Ready
v1.2.2 | Apache-2.0 | 208 Downloads

Calculate the development cost savings from using open source software by analyzing SBOMs or package lists using COCOMO II models

View on GitHub