#SCANOSS
コードベースに混入したOSSコンポーネントを自動検出し、ライセンス違反や既知の脆弱性を可視化できるツール。SCA(Software Composition Analysis)ツールと呼ばれる。メモ。
SCANOSS CLIでローカルスキャン:インストールからSBOM生成まで | SIOS Tech Lab
SCAツールSCANOSSのPython CLI(scanoss-py)を使ったローカルスキャンの手順を紹介。インストールからスキャン結果の読み方、scanoss.jsonによる誤検出チューニング、SBOM生成、ScanCode Toolkit連携の依存関係スキャンまで実際の検証結果とともにお伝えします。
tech-lab.sios.jp
March 8, 2026 at 10:05 AM
📦 gumslone/laravel-purl2cpe v2.3.0

PURL to CPE conversion for Laravel, backed by the curated scanoss/purl2cpe database. Ships ~47k reduced mappings so you can resolve NVD CPEs for a Package URL out of the box.

🔗 https://github.com/gumslone/laravel-purl2cpe
September 22, 2026 at 7:18 PM
Ever get tired of re-triaging the same snippet findings every time you scan your codebase?
If you’re using SCANOSS with ORT, this one’s for you.
June 18, 2025 at 11:15 AM
Heading to #PQC2025?

Join IBM, The Linux Foundation, and SCANOSS for the CBOM Hands-On Workshop
28 Oct, 9 AM, Room 1.

#CBOM #CycloneDX #CryptoAgility #OpenSource #SCANOSS
October 25, 2025 at 3:44 PM
October 1, 2024 at 7:30 PM
Full breakdown of how SCANOSS + snippet_choices works, with examples:
👉 scanoss.com/post/oss-rev...
If you’re using SCANOSS with ORT, this is a small change that makes a big difference.
June 18, 2025 at 11:16 AM
SBOMツール紹介 ~SCANOSS編 ~ ③PythonのSDK「scanoss.py」 | SIOS Tech. Lab
SBOMツール紹介 ~SCANOSS編 ~ ③PythonのSDK「scanoss.py」 | SIOS Tech. Lab
はじめに こんにちは!SBOMツールを調査中のなーがです。前回に引き続きSCANOSSについてみていきます。今
tech-lab.sios.jp
October 16, 2024 at 5:06 PM
We’re SCANOSS

We scan code. We find stuff. We tell you what’s up.

Old licences, odd vulnerabilities, mystery files from the depths of the repo… we find it, so you don’t have to.
a lizard is standing on its hind legs and dancing .
ALT: a lizard is standing on its hind legs and dancing .
media.tenor.com
May 19, 2025 at 10:00 AM
Me: “This release looks clean.”
SCANOSS: “There’s a CVE in that transitive dependency you forgot about.”
May 23, 2025 at 1:28 PM
うーむ。これどうやって「別の人物の権利を侵害していないこと」を確認するんだろう?まさか著者に丸投げ?

コンピュータのプログラム、コードの場合はScanOSSといった「AIが出力したコードが巷のOSSのライセンスを侵害していないか」をチェックしてくれるユーティリティがあったりするのだが、文章にも同じようなサービスが既にどこかに存在するのだろうか?
www.scanoss.com
March 29, 2026 at 11:51 AM
Discover Bringing open collaboration into new fields through cryptographic algorithms with Phyto Michael, Sales Director, SCANOSS. Watch the full video from SOOCon25: openuk.uk/soocon/ #opensource #opendata #soocon25 #stateofopencon
May 1, 2025 at 1:05 PM
When you match outfits and missions 💥
The SCANOSS crew is suited up and ready to bring serious crypto energy to Infosecurity Europe
Come find us at Booth B152 on the discovery zone!
June 4, 2025 at 1:27 PM
Listened to The Business of Open Source | AI-generated Code Copied from Open Source with Julian Coccia Post details

> This week on The Business of Open Source, I spoke with Julian Coccia, CTO of ScanOSS, about selling access to data while making open source software. Of course, we also talked […]
Original post on jvt.me
www.jvt.me
May 10, 2025 at 9:40 PM
ntroducing High Precision Folder Matching (HPFM) for smarter open source scanning — now in scanoss-py

Traditional scanners go file by file. That’s great for granularity… but what if you just want to know what project you’re looking at?

Enter: HPFM.
a group of soccer players with the number 16 on their back
ALT: a group of soccer players with the number 16 on their back
media.tenor.com
June 30, 2025 at 11:08 AM
Just shipped: SCANOSS Container Scanning.

Containers are more than your app — they carry hundreds of hidden dependencies. We now scan the whole thing and give you a complete SBOM, including undeclared components.

📦 Transparency, finally.
www.scanoss.com/post/introdu...
Introducing Container Scanning: Deeper Insight into Dependencies
We’re constantly evolving our open source intelligence to help teams achieve full transparency over the software they build and deploy. We’re have now added Container Scanning — giving development, se...
www.scanoss.com
May 28, 2025 at 1:17 PM
📦 gumslone/laravel-purl2cpe v2.2.0

PURL to CPE conversion for Laravel, backed by the curated scanoss/purl2cpe database. Ships ~47k reduced mappings so you can resolve NVD CPEs for a Package URL out of the box.

🔗 https://github.com/gumslone/laravel-purl2cpe
August 8, 2026 at 2:08 PM