I built CheckRisks to help teams using Jira Cloud assess and track risks when linking third-party components to their development tasks.
Many teams include GitHub snapshots (e.g. a commit or repo link) in Jira issues. CheckRisks automatically analyzes those references and highlights known vulnerabilities, outdated dependencies, and license risks—right inside Jira.
Key features: • Automatic risk assessment of any public GitHub repo or commit • Tracks open issues (e.g. CVEs, deprecations) • Pin the most relevant risks inside Jira cards • Works with public components — no GitHub auth required
A free basic edition is available on the Atlassian Marketplace. You can install it and start using it right away.