OpenSSF project
GUAC
Graph for Understanding Artifact Composition — a queryable supply-chain knowledge graph that aggregates SBOMs, attestations, and vulnerability data.
How each persona uses GUAC
Software Developer / Maintainer Developer
Queries GUAC to understand the exact dependency graph and vulnerability blast radius for the components they are actively developing.
Open Source Professional (OSPO) OSPO
Leverages GUAC to maintain a comprehensive, queryable graph of software supply chain metadata across all enterprise projects.
Security Engineer / Architect Security
Utilizes GUAC to establish architectural traceability of published components across the software supply chain.
CI/CD DevOps & Tooling Integrator DevOps
Integrates GUAC into the pipeline to automatically block builds that introduce malicious or policy-violating transitive dependencies.
Package & Repository Manager Package Manager
Leverages GUAC to expose actionable metadata about components and their relationships for supply chain integrity.
Executive / End-User Consumer Executive
Relies on GUAC's high-level supply chain visibility to understand enterprise risk exposure during major zero-day vulnerability events.
Problems GUAC helps with
Dependency & SBOM Visibility Visibility
Aggregates SBOMs and attestations into one queryable graph so you can trace any component and its relationships.
Vulnerability Management Vulnerabilities
Joins vulnerability data to the dependency graph to reveal the blast radius of a newly disclosed flaw.
Relationships
Outgoing
- consumesSoftware Bill of Materialspublication
- consumesSLSA Provenancepublication