OSS Risk Report

Acme Corp

github.com/Risk-Guard/public-test — Feb 25, 2026

OSS Risk Guard
Bonded Risk Report
Executive Summary

This SBOM introduces $2.3M in incremental annual engineering overhead above industry baseline, bringing total adjusted overhead to $4.8M (9.5% of target revenue). The primary driver is a 3.2× maintenance burden from unmaintained dependencies.

5 critical packages require immediate review. Dependency failure probability is 2.7× peer average. Security breach exposure is favorable at 3.1× below comparable companies.

Section 01

What you're acquiring

Asset identity and company profile

Asset Identity
Repository github.com/Risk-Guard/public-test
Scan Date Feb 25, 2026
Ecosystems 4
npm 92 PyPI 49 RubyGems 69 GitHub 1
Company Profile
Annual Revenue $50,000,000
Customer Records 100,000
Developers 50
Region United States

Every company running open source carries these costs

Calculated from this company's profile: 50 developers × $150K fully-loaded, $50,000,000 revenue, 100,000 customer records, United States.

Incidents

Low-probability, high-impact events. You don't budget for these — you price the exposure.

Security Breach $10,220,000
80.0% annual probability EAL $8,176,000
Dependency Failure $75,000
12.0% annual probability EAL $9,000
IP Litigation $1,000,000
6.0% annual probability EAL $60,000

Engineering Drag

of $7,500,000 engineering budget

Ongoing overhead. Time your developers spend maintaining dependencies instead of building product.

Security Patches
$1,425,000 19.0%
Maintenance Burden
$945,000 12.6%
License Remediation
$42,550 0.6%
Total OSS Overhead
$2,412,550 32.2%

EAL = Expected Annual Loss (probability × per-incident cost). Developer costs assume $150,000/yr fully-loaded.

Health Snapshot
211
Packages
380
Findings
16%
Clean
4
Ecosystems
16% of packages passed all checks
Section 02

What it costs relative to baseline

Expected costs based on scan results vs. industry average for this company profile

Annual Engineering Overhead
Category Baseline Drag Adjusted Delta
Maintenance Burden $945,000 3.2× $3,061,261 +$2,116,261
Security Patches $1,425,000 1.1× $1,609,612 +$184,612
License Remediation $42,550 2.1× $89,045 +$46,495
Total $2,412,550 $4,759,918 +$2,347,368
Per-Incident Exposure
Incident Type Per-Incident Cost Baseline Prob. Adjusted Prob. EAL
Security Breach $10,220,000 80.0% 26.0% $2,656,865
Dependency Failure $75,000 12.0% 32.1% $24,045
IP Litigation $1,000,000 6.0% 8.2% $82,124

EAL = Expected Annual Loss (probability × per-incident cost). Baseline assumes industry average for this company profile.

Engineering Drag — Team of 5 vs. Comparable Companies
Maintenance Burden
3.2×
3.2× the engineering time working around unmaintained dependencies
Security Patches
1.1×
1.1× the engineering time on vulnerability patches
License Remediation
2.1×
2.1× the engineering time swapping out banned licenses
Relative Risk Exposure vs. Comparable Companies
Security Breach
3.1×
3.1× less likely to have a security breach than comparable companies
Below peer average
Dependency Failure
2.7×
2.7× more likely to face a service disruption or forced migration than comparable companies
IP Litigation
1.4×
1.4× more likely to face an IP claim from non-compliant licenses than comparable companies
Section 03

This is the proof

Critical findings driving the numbers above

5 Critical
17 High
84 Medium
274 Low
5 Critical Packages — Immediate Review Required
Check Packages Detail
SOURCE_NO_LICENSE 4

Without a license, the code is under exclusive copyright by default, making any use potentially infringing

importlib-metadata · rdoc · zipp · minitest

PACKAGE_NAME_MISMATCH 1

A name mismatch between published package and source repository enables package impersonation or substitution attacks.

f-ask

Full findings table (380 findings across 211 packages) available in the appendix.

See All Findings →

380 findings across 211 packages

This report was generated by OSS Risk Guard on Feb 25, 2026. All developer cost calculations assume a fully-loaded salary of $150,000/year.
ossriskguard.com