FOSSA CLI is a command-line tool that scans your codebase to identify open-source dependencies and their associated licenses and vulnerabilities. It integrates into CI/CD pipelines to provide automated compliance checks, license audits, and security analysis. Designed for enterprise software teams, FOSSA CLI helps enforce open-source policies at scale and provides accurate, automated insights into third-party software usage through deep analysis of transitive dependencies and ecosystem-specific configurations.
Features
- Scans code for open-source dependencies and licenses
- Detects license conflicts and policy violations
- Identifies known vulnerabilities in dependencies
- Integrates with CI/CD for automated compliance
- Supports multiple languages and build tools
- Exports detailed reports in multiple formats
