{"categories":[{"label":"Software Development","url":"https://skillfed.io/packages/category/software-development/16"},{"label":"Utilities","url":"https://skillfed.io/packages/category/utilities/9"}],"enrichment":{"capability":"ScanCode Toolkit detects licenses, copyrights, package metadata, and dependencies in source code and binary files, and outputs results in multiple formats including JSON, YAML, HTML, CycloneDX, and SPDX.","skillfed_tags":["license-compliance","sbom-generation","supply-chain-security"],"use_cases":["Generate software bill of materials (SBOM) in SPDX or CycloneDX format for compliance and supply-chain transparency.","Scan open-source dependencies and third-party code to identify license obligations before integration.","Integrate into CI/CD pipelines to enforce license policies and detect copyright notices automatically.","Extract package metadata and dependencies from manifests and lockfiles for dependency tracking.","Audit binary packages and compiled artifacts for embedded licenses and copyright information."],"what_it_does":"ScanCode Toolkit is a production-grade code scanning tool that identifies licenses, copyrights, package manifests, and dependencies across source and binary files. It performs full-text comparison against a database of license texts rather than relying on regex patterns alone, and is used by hundreds of software teams including the Eclipse Foundation, FSFE, and FSF. The toolkit runs as both a command-line tool and an embeddable library, with support for Windows, macOS, and Linux.\n\nThe package outputs scan results in multiple formats (JSON, YAML, HTML, CycloneDX, SPDX) and can be extended via plugins for custom scanners and parsers. It includes support for parsing package manifests and lockfiles to extract Package URLs and metadata. The project is actively maintained, heavily tested with over 30,000 tests per commit, and backed by European Commission NGI funding.","worth_installing":"Yes. ScanCode Toolkit is a mature, actively maintained tool with no known vulnerabilities, low install friction, and permissive licensing. It is the reference implementation for code scanning depth and accuracy, widely adopted by major organizations. Install it if you need license detection, copyright extraction, or SBOM generation; the 50 runtime dependencies are standard utilities and the command-line interface is straightforward to integrate into existing workflows."},"id":"scancode-toolkit","links":{"html":"https://skillfed.io/packages/scancode-toolkit","md":"https://skillfed.io/packages/scancode-toolkit.md","pypi":"https://pypi.org/project/scancode-toolkit/"},"maintenance":{"status":"active"},"meta":{"latest_release":"2026-01-15","license_spdx":null,"license_treatment":"permissive","name":"scancode-toolkit","python_support":"supports_current","summary":"ScanCode is a tool to scan code for license, copyright, package and their documented dependencies and other interesting facts."},"popularity":{"monthly_downloads":122869,"position":11928,"tier":"top_15000"},"security":{"n_vulnerabilities":0},"version":"32.5.0"}
