OpenSSF project

GUAC

Graph for Understanding Artifact Composition — a queryable supply-chain knowledge graph that aggregates SBOMs, attestations, and vulnerability data.

How each persona uses GUAC

Software Developer / Maintainer Developer

Queries GUAC to understand the exact dependency graph and vulnerability blast radius for the components they are actively developing.

See everything for Developer →

Open Source Professional (OSPO) OSPO

Leverages GUAC to maintain a comprehensive, queryable graph of software supply chain metadata across all enterprise projects.

See everything for OSPO →

Security Engineer / Architect Security

Utilizes GUAC to establish architectural traceability of published components across the software supply chain.

See everything for Security →

CI/CD DevOps & Tooling Integrator DevOps

Integrates GUAC into the pipeline to automatically block builds that introduce malicious or policy-violating transitive dependencies.

See everything for DevOps →

Package & Repository Manager Package Manager

Leverages GUAC to expose actionable metadata about components and their relationships for supply chain integrity.

See everything for Package Manager →

Executive / End-User Consumer Executive

Relies on GUAC's high-level supply chain visibility to understand enterprise risk exposure during major zero-day vulnerability events.

See everything for Executive →

Problems GUAC helps with

Dependency & SBOM Visibility Visibility

Aggregates SBOMs and attestations into one queryable graph so you can trace any component and its relationships.

See everything for Visibility →

Vulnerability Management Vulnerabilities

Joins vulnerability data to the dependency graph to reveal the blast radius of a newly disclosed flaw.

See everything for Vulnerabilities →

Relationships

Outgoing