Back to Portfolio

Open-Source Compliance Cockpit

A modern SCA workspace that turns open-source license risk into visual, immediately actionable answers.

Summary
License compliance auditing traditionally means complex CLI tools and developers reading impenetrable reports. In this project an original research thesis was fully refactored into a modern React/Node.js application, introducing interactive dependency trees and real-time package checking (the What-if Playground) before installation. The result is an automated tool that bridges the gap between engineering and legal teams, protecting the codebase and making it safer to scale.
124
Overview

Risk management in modern software is no longer only a technical question — it is a legal one. What follows is the vision, the evolution and the business value of this project, and how tooling can simplify a genuinely complicated compliance process.

1. The Problem: The Invisible Risk in Open Source

Open-source software is the engine behind every modern product, letting teams build and ship at a pace that would otherwise be impossible. But behind the convenience of installing a ready-made package sits a risk that is routinely overlooked: license compliance. A single dependency buried deep in a project’s tree can carry a restrictive license (such as the GPL) that legally obliges a company to open-source its entire commercial codebase.

Despite how serious that exposure is, auditing for it remains one of the sharpest thorns in the development lifecycle. Traditional software composition analysis (SCA) tools are built to emit enormous lists of opaque data that require specialist knowledge to interpret. The result is constant friction between developers who need to ship quickly and companies that need legal and commercial protection.

2. The Journey: From Research Proof-of-Concept to a Real Product

This tool did not start yesterday. Its roots are in my undergraduate thesis, completed five years ago. The goal then was to prove technically that automated detection of these legal conflicts was feasible, by developing an initial repository-scanning algorithm. It was a successful research model, but built on the technical assumptions of its time.

Recognising the gap in the market for tools that are genuinely usable, I revived the project with a complete, ground-up refactor. I abandoned the old architecture and rebuilt the application from scratch on modern foundations, moving to a React and Node.js stack. The aim was not simply to modernise the code, but to turn an internal script into a complete, extensible tool capable of standing as a SaaS product in today’s software ecosystem.

3. The Philosophy: Developer Experience as a Bridge

The central strategic decision for the new product was to put developer experience first. Developers want to solve problems, not interpret legal texts. So the system was designed to translate complex legal terminology into plain, everyday English. It gives the user a clear, direct answer: why a package is dangerous, and exactly what to do about it.

At the same time, the platform acts as a translator between engineering and the legal or management side of a business. Lawyers and managers cannot reasonably be expected to parse technical terms or code evidence. The tool bridges that gap by exporting clean, non-technical Legal Reports that summarise a project’s risk and make decisions possible at a business level.

4. Capability: Preventing Rather Than Curing (Shift-Left)

One of the most useful features built into the platform is the What-if Playground. Instead of waiting for a developer to finish the code, push it to GitHub and only then be audited, the Playground lets them test the packages they intend to use before writing the first line. It is shift-left applied in practice: catching red flags at the design stage and saving countless hours of code that would otherwise have to be rewritten.

The system also moves away from traditional error lists by introducing a visual dependency graph, so the user can see the exact path to a problematic dependency. More importantly, the tool does not stop at reporting the problem — it automatically suggests safer alternative open-source libraries, turning a passive audit into something immediately actionable.

5. The Outcome: Protecting Innovation at Scale

The real impact of a platform like this is that it frees teams to build inside a controlled, safe boundary. For companies scaling their products, that means protecting their intellectual property and avoiding damaging legal complications. For open-source maintainers, it means safeguarding the integrity of their projects against accidental, license-contaminating third-party contributions.

Finishing this project reflects a broader view I hold as an engineer: advanced technical complexity only has value when it serves a person and a business. The evolution of this application shows that the most successful tools are the ones that manage to hide the heavy computation and the research algorithms behind a clean, intuitive, solution-oriented interface.

Machine Learning Full-Stack Dev Computer Vision Cloud Architecture Data Science Deep Learning System Optimization UI / UX Design API Integration Experience Database Management Machine Learning Full-Stack Dev Computer Vision Cloud Architecture Data Science Deep Learning System Optimization UI / UX Design API Integration Experience Database Management
Valuable Feedback

Trusted By the World's Fastest Growing Companies

Digital product design and scalable web platforms

[2022-2025]

0 % Growth
Knowledge-driven systems and content architecture

[2023-2024]

0 % Growth
Lightweight development for high-performance products

[2020-2026]

0 % Growth
AUTh
bos
UOP
QuickFind
Business Managmenet
logo