Global-OSS
Top drivers
⌁ mcp.call("adw-339") vADW-339-live-1.0 Is the OSS software supply chain under elevated vulnerability pressure, and where?
Global-OSS
Top drivers
⌁ mcp.call("adw-339") vADW-339-live-1.0 A DevSecOps automation agent polls ADW-339 weekly and, when the CVSS-weighted score rises above 50 (current: 28.8 on first observation—moderate pressure), it immediately cross-references the top_drivers field to identify which packages in the npm+PyPI basket are driving pressure, then opens prioritized upgrade tickets in the issue tracker and blocks any pipeline deployment that depends on the flagged packages until they are remediated. The source_lineage back to deps.dev (Google's Open Source Insights) and methodology_version (per-package CVSS3 sum / max normalization) give the security team a reproducible audit trail required under SOC 2 and NIST SSDF compliance frameworks.
A CISO at a SaaS company uses ADW-339 as an executive-layer signal to track whether the open-source ecosystem their engineering teams depend on is entering a period of elevated vulnerability pressure—without requiring them to parse individual CVE feeds. A score of 28.8 signals manageable baseline pressure today, but the trend field enables the CISO to present a forward-looking vulnerability posture to the board on a consistent weekly cadence, replacing a patchwork of Snyk and Dependabot dashboards that differ by team and lack a single comparable number across quarters.
per-pkg sum(cvss3) over recent GA versions / max -> mean across basket -> 0-100
Version ADW-339-live-1.0 · validated to beat a naive baseline · benchmark: Sonatype SOSS; Snyk State of OSS; OSS Index