
Application SecuritySupply Chain Security
FOSSA Scan
Universal supply chain scanning for license compliance, SBOM management, and dependency CVEs.
FOSSA Scan Overview
What it does
FOSSA Scan is a software supply chain scanner that inventories third-party code across packages, containers, Software Bills of Materials (SBOMs), binaries, and code snippets to manage open source license compliance and dependency risk. The platform runs universal dependency analysis for 30+ languages through a zero-configuration cloud scan or the fossa-cli, pairing full-text license detection with 99.8% accuracy on non-standard and modified licenses with CVE identification, filtering, and prioritization.
How it works
Scans run from the CLI, CI/CD pipelines, or connected code hosts, resolving dependency graphs to unlimited depth and applying reachability-based Software Composition Analysis (SCA) so findings prioritize vulnerabilities reachable in production. A policy engine enforces pre-vetted or custom license and security rules during development, and a remediation algorithm weighs exploitability, upgrade impact, and effort to recommend fixes; fossabot adds automated pull-request checks and dependency updates. Reporting generates audit-grade attribution notices and SBOM exports in CycloneDX and SPDX, and imported third-party SBOMs are monitored against live vulnerability feeds. F5 NGINX uses the platform to automate SBOM generation.
Credentials and traction
FOSSA maintains SOC 2 compliance and was named a Niche Player in the inaugural 2026 Gartner Magic Quadrant for Software Supply Chain Security. Customers include UiPath, Collibra, Cloudera, DigiCert, Confluent, Applause, Lattice, and the U.S. Navy, alongside Cloud Native Computing Foundation projects. The platform's SBOM tooling supports Executive Order 14028 and NTIA minimum elements compliance, serving enterprise legal, security, and engineering teams.
Key Capabilities
mapped to solution categoriesGenerates SBOMs from source code analysis (via build system integration), and from binary analysis (via binary composition analysis), the latter enabling SBOM generation for third-party software where source is unavailable.
Imports and exports SBOMs in CycloneDX, SPDX, and SWID formats, enabling interoperability with scan tools, procurement workflows, and regulatory evidence systems.
Tracks license obligations across the SBOM inventory, identifying GPL and AGPL copyleft propagation, license conflicts, and FOSS obligations for each release.
Generates formatted evidence packages for SBOM-related regulatory requirements: FDA pre-market cybersecurity guidance, Executive Order 14028 SBOM requirements, EU Cyber Resilience Act Article 13.
Monitors SBOMs against live vulnerability feeds, alerts when new CVEs affect components in managed SBOMs. Latency to alert after new CVE publication varies.
Manages the SBOM life cycle including discovery, access and secure exchange between software suppliers and consumers.
Creates, imports, and manages Vulnerability Exploitability eXchange statements asserting the exploitability status of CVEs for specific product versions, reducing false positive noise for downstream consumers.
Traverses the full dependency graph to surface CVEs in indirect dependencies, packages required by your direct dependencies. Direct-only scanning misses the majority of vulnerable code paths in modern polyglot projects.
Identifies OSS licenses in the dependency tree and flags conflicts with the project's target license or policy (GPL contamination, copyleft obligations, export-controlled components). Separate from vulnerability detection.
Determines whether a vulnerable function is actually reachable and called in the codebase: not merely present in the dependency tree. Reduces actionable CVEs to those with real exploit paths; requires static code analysis on top of dependency scanning.
Exports the dependency inventory as a machine-readable Software Bill of Materials in SPDX or CycloneDX format, consumable by downstream vulnerability scanners, compliance tools, and procurement workflows.
Identifies open source and third-party components in compiled binaries and closed-source artifacts where no package manifest exists.
Blocks or flags PRs in CI/CD pipelines based on policy-defined thresholds, configurable by severity, CVSS score, exploitability, fix availability, or CVE age. Prevents vulnerable code from merging without requiring zero-tolerance policies.
Opens PRs with upgraded dependency versions that resolve CVEs. Quality differentiation is whether the fix resolves transitive chains or only direct dependencies, and whether the PR is merge-safe without manual review.
Prioritizes dependency vulnerabilities using exploitation signals such as EPSS probability and the CISA Known Exploited Vulnerabilities catalog, ranking findings by real-world exploitation likelihood rather than CVSS severity alone.
Risk context for open-source dependencies including reachability, exploitability, and upgrade impact.
Governs third-party software consumption to apply consistent software supply chain security policy.
Live visibility into code, components, pipelines, and developer activity across the software development lifecycle.
On-demand generation of software, firmware, and hardware bills of materials (SBOM, FBOM, HBOM) for endpoints, servers, and network devices, extending component inventory below the application layer.
Integrations
compatible toolsImplementation & support
Info last updated on August 1, 2026
Buyers
See how FOSSA Scan fits your stack
Add FOSSA Scan to your shortlist and unlock all evaluation tools.
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.