
Application SecuritySupply Chain Security
FOSSA Scan
Universal supply chain scanning for license compliance, SBOM management, and dependency CVEs.
FOSSA Scan Overview
What it does
FOSSA Scan is a software supply chain scanner that inventories third-party code across packages, containers, Software Bills of Materials (SBOMs), binaries, and code snippets to manage open source license compliance and dependency risk. The platform runs universal dependency analysis for 30+ languages through a zero-configuration cloud scan or the fossa-cli, pairing full-text license detection with 99.8% accuracy on non-standard and modified licenses with CVE identification, filtering, and prioritization.
How it works
Scans run from the CLI, CI/CD pipelines, or connected code hosts, resolving dependency graphs to unlimited depth and applying reachability-based Software Composition Analysis (SCA) so findings prioritize vulnerabilities reachable in production. A policy engine enforces pre-vetted or custom license and security rules during development, and a remediation algorithm weighs exploitability, upgrade impact, and effort to recommend fixes; fossabot adds automated pull-request checks and dependency updates. Reporting generates audit-grade attribution notices and SBOM exports in CycloneDX and SPDX, and imported third-party SBOMs are monitored against live vulnerability feeds. F5 NGINX uses the platform to automate SBOM generation.
Credentials and traction
FOSSA maintains SOC 2 compliance and was named a Niche Player in the inaugural 2026 Gartner Magic Quadrant for Software Supply Chain Security. Customers include UiPath, Collibra, Cloudera, DigiCert, Confluent, Applause, Lattice, and the U.S. Navy, alongside Cloud Native Computing Foundation projects. The platform's SBOM tooling supports Executive Order 14028 and NTIA minimum elements compliance, serving enterprise legal, security, and engineering teams.
Key Capabilities
mapped to solution categoriesGenerates SBOMs from source code analysis (via build system integration), and from binary analysis (via binary composition analysis), the latter enabling SBOM generation for third-party software where source is unavailable.
Imports and exports SBOMs in CycloneDX, SPDX, and SWID formats, enabling interoperability with scan tools, procurement workflows, and regulatory evidence systems.
Tracks license obligations across the SBOM inventory, identifying GPL and AGPL copyleft propagation, license conflicts, and FOSS obligations for each release.
Generates formatted evidence packages for SBOM-related regulatory requirements: FDA pre-market cybersecurity guidance, Executive Order 14028 SBOM requirements, EU Cyber Resilience Act Article 13.
Monitors SBOMs against live vulnerability feeds, alerts when new CVEs affect components in managed SBOMs. Latency to alert after new CVE publication varies.
Manages the SBOM life cycle including discovery, access and secure exchange between software suppliers and consumers.
Creates, imports, and manages Vulnerability Exploitability eXchange statements asserting the exploitability status of CVEs for specific product versions, reducing false positive noise for downstream consumers.
Normalizes ingested SBOMs to the CISA minimum elements by resolving missing or inaccurate component identifiers such as PURL and CPE and dependency relationships, and enriches components with license, supplier and support metadata, so SBOMs from any generator can be analyzed for third-party risk consistently.
Searches the organization-wide SBOM inventory by component, version or CVE and returns the affected products, projects and environments, so a newly disclosed vulnerability or a suspect package can be traced to everywhere it ships.
Validates imported SBOMs against minimum-element requirements (NTIA baseline and successor CISA guidance), flagging missing supplier names, versions, unique identifiers, and dependency relationships before the SBOM is exchanged or submitted as regulatory evidence. Checks declared data-field completeness rather than verifying declarations against compiled binaries.
Traverses the full dependency graph to surface CVEs in indirect dependencies, packages required by your direct dependencies. Direct-only scanning misses the majority of vulnerable code paths in modern polyglot projects.
Identifies OSS licenses in the dependency tree and flags conflicts with the project's target license or policy (GPL contamination, copyleft obligations, export-controlled components). Separate from vulnerability detection.
Determines whether a vulnerable function is actually reachable and invoked, not merely present in the dependency tree, cutting actionable CVEs down to those with real exploit paths. Delivered either statically, by call-graph analysis layered on dependency scanning, or at runtime, by instrumenting the workload to observe which components actually execute.
Exports the dependency inventory as a machine-readable Software Bill of Materials in SPDX or CycloneDX format, consumable by downstream vulnerability scanners, compliance tools, and procurement workflows.
Identifies open source and third-party components in compiled binaries and closed-source artifacts where no package manifest exists.
Blocks or flags PRs in CI/CD pipelines based on policy-defined thresholds, configurable by severity, CVSS score, exploitability, fix availability, or CVE age. Prevents vulnerable code from merging without requiring zero-tolerance policies.
Opens PRs with upgraded dependency versions that resolve CVEs. Quality differentiation is whether the fix resolves transitive chains or only direct dependencies, and whether the PR is merge-safe without manual review.
Prioritizes dependency vulnerabilities using exploitation signals such as EPSS probability and the CISA Known Exploited Vulnerabilities catalog, ranking findings by real-world exploitation likelihood rather than CVSS severity alone.
Identifies packages with known-malicious behavior (typosquatting, dependency confusion, backdoored releases), distinct from packages with CVEs in legitimate code.
Imports or generates Vulnerability Exploitability eXchange documents asserting whether a known CVE actually affects a given product in its deployed context, including statements derived from reachability analysis so an SBOM ships with evidence-backed exploitability. Reduces false positives in downstream consumers of SBOMs.
Risk context for open-source dependencies including reachability, exploitability, and upgrade impact.
Governs third-party software consumption to apply consistent software supply chain security policy.
Live visibility into code, components, pipelines, and developer activity across the software development lifecycle.
On-demand generation of software, firmware, and hardware bills of materials (SBOM, FBOM, HBOM) for endpoints, servers, and network devices, extending component inventory below the application layer.
Integrations
compatible toolsImplementation & support
Info last updated on September 7, 2026
Buyers
Start a shortlist with FOSSA Scan
Compare options, add your notes, and run informed evaluations.
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.