$npx skillfedfor your agent

scancode-toolkit

ScanCode is a tool to scan code for license, copyright, package and their documented dependencies and other interesting facts.

Worth itPyPI Software DevelopmentReleased Jan 2026122.9K downloads / mopermissive licensePure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — scancode_toolkit-32.5.0-cp310-none-any.whl · scancode_toolkit-32.5.0-cp311-none-any.whl · scancode_toolkit-32.5.0-cp312-none-any.whl
v32.5.0 · released 2026-01-15 · Python >=3.10 · 50 runtime deps: attrs, Beautifulsoup4, boolean.py, chardet, click, colorama, commoncode, container-inspector

Yes. ScanCode Toolkit is a mature, actively maintained tool with no known vulnerabilities, low install friction, and permissive licensing. It is the reference implementation for code scanning depth and accuracy, widely adopted by major organizations. Install it if you need license detection, copyright extraction, or SBOM generation; the 50 runtime dependencies are standard utilities and the command-line interface is straightforward to integrate into existing workflows.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10 or later; the package is designed primarily as a command-line tool, so library usage patterns may require consulting the documentation.
  • Low install friction with wheels available for Python 3.10 through 3.14.
  • Active maintenance with last commit on 2026-08-07 and 2602 repository stars.

License · maintenance · safety

permissive license (permissive) — Licensed under Apache-2.0 with CC-BY-4.0 for reference datasets and multiple secondary permissive or copyleft licenses for third-party components. Permissive overall treatment allows commercial and proprietary use, though you should review the NOTICE file and .ABOUT files for third-party attribution obligations.

last release 2026-01-15 (211 days) · last repo commit 2026-08-07 · 2,602 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 122,869 downloads/mo, #11,928 on PyPI

Verify before relying

pip install scancode-toolkit

from scancode.cli import main
main(['--license', '--copyright', '/path/to/code'])
  • Whether the package's 50 runtime dependencies introduce significant disk or memory overhead in production environments.
  • Performance characteristics when scanning very large codebases or binary files.
  • Accuracy of license detection compared to other SCA tools in your specific use case.
Same gist for agents: .md · .json

What it is and what it does

ScanCode Toolkit is a production-grade code scanning tool that identifies licenses, copyrights, package manifests, and dependencies across source and binary files. It performs full-text comparison against a database of license texts rather than relying on regex patterns alone, and is used by hundreds of software teams including the Eclipse Foundation, FSFE, and FSF. The toolkit runs as both a command-line tool and an embeddable library, with support for Windows, macOS, and Linux.

The package outputs scan results in multiple formats (JSON, YAML, HTML, CycloneDX, SPDX) and can be extended via plugins for custom scanners and parsers. It includes support for parsing package manifests and lockfiles to extract Package URLs and metadata. The project is actively maintained, heavily tested with over 30,000 tests per commit, and backed by European Commission NGI funding.

Use it for

  • Generate software bill of materials (SBOM) in SPDX or CycloneDX format for compliance and supply-chain transparency.
  • Scan open-source dependencies and third-party code to identify license obligations before integration.
  • Integrate into CI/CD pipelines to enforce license policies and detect copyright notices automatically.
  • Extract package metadata and dependencies from manifests and lockfiles for dependency tracking.
  • Audit binary packages and compiled artifacts for embedded licenses and copyright information.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

ScanCode Toolkit is a mature, actively maintained tool with no known vulnerabilities, low install friction, and permissive licensing. It is the reference implementation for code scanning depth and accuracy, widely adopted by major organizations. Install it if you need license detection, copyright extraction, or SBOM generation; the 50 runtime dependencies are standard utilities and the command-line interface is straightforward to integrate into existing workflows.

Install

scancode-toolkit on PyPI

Before you install

Low install friction with wheels available for Python 3.10 through 3.14. Active maintenance with last commit on 2026-08-07 and 2602 repository stars. Depends on 50 runtime packages including common utilities like click, lxml, and jinja2, but no compiled system dependencies are evident from the wheel availability.

Requires Python 3.10 or later; the package is designed primarily as a command-line tool, so library usage patterns may require consulting the documentation.

License in practice

Licensed under Apache-2.0 with CC-BY-4.0 for reference datasets and multiple secondary permissive or copyleft licenses for third-party components. Permissive overall treatment allows commercial and proprietary use, though you should review the NOTICE file and .ABOUT files for third-party attribution obligations.

Quickstart

pip install scancode-toolkit

from scancode.cli import main
main(['--license', '--copyright', '/path/to/code'])

Verify before relying

  • Whether the package's 50 runtime dependencies introduce significant disk or memory overhead in production environments.
  • Performance characteristics when scanning very large codebases or binary files.
  • Accuracy of license detection compared to other SCA tools in your specific use case.

Package facts

Licensepermissive license permissive
Python supportSupports the current Python release >=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
50 packages
attrsBeautifulsoup4boolean.pychardetclickcoloramacommoncodecontainer-inspectorcyseqdebian-inspectordparse2fastenersfingerprintsftfygemfileparser2html5libimportlib_metadataintbitsetjaraco.functoolsjavapropertiesjinja2jsonstreamslicense_expressionlxmlMarkupSafemultiregexnormalitypackageurl_pythonpackversparameter-expansion-patched
MaintenanceActively maintained 211 days since the last release
Last repo commit
First released
Downloads122,869 / month, #11,928 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableIntended Audience :: DevelopersProgramming Language :: Python :: 3Programming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Topic :: Software DevelopmentTopic :: Utilities

Evidence: scancode_toolkit-32.5.0-cp310-none-any.whl; scancode_toolkit-32.5.0-cp311-none-any.whl; scancode_toolkit-32.5.0-cp312-none-any.whl; scancode_toolkit-32.5.0-cp313-none-any.whl; scancode_toolkit-32.5.0-cp314-none-any.whl

Tags

Capabilities
license detection in codecopyright and license scannersoftware composition analysisSBOM generationdependency and package detectionsource code scanning toollicense compliance checker
Topics
license-compliancesbom-generationsupply-chain-security
PyPI keywords
open sourcescanlicensepackagedependencycopyrightfiletypeauthorextractlicensingscanscaSBOMspdxcyclonedx

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “license detection in code”

  • scancode-toolkitScanCode Toolkit detects licenses, copyrights, package metadata, and…
  • scanossScanoss provides a Python library and CLI tool to fingerprint source…
  • cyseqcyseq provides a Cython-optimized implementation of sequence matching…

Give your agent the search over MCP, or paste the wish link into any chat.

More Software Development packages

typing-extensions Worth it
PyPI · Software Development · released Jul 2026

Provides backported and experimental type hints for Python 3.9+, allowing use of newer typing features on older Python versions and enabling early experimentation with type system PEPs before they enter the standard library.

PSF-2.0pure Python · 3.9+
1.9Bdownloads / mo
numpy Worth it
PyPI · Software Development · released Aug 2026

NumPy provides an N-dimensional array object and a comprehensive suite of mathematical, linear algebra, Fourier transform, and random number functions for scientific computing in Python.

BSD-3-Clause AND 0BSD AND MIT AND Zlib AND CC0-1.0compiled wheel · 3.12+
1.1Bdownloads / mo
fastapi Worth it
PyPI · Software Development · released Jul 2026

FastAPI is a Python web framework for building REST APIs using type hints, with automatic request validation, serialization, and interactive API documentation.

MITpure Python · 3.10+
568.6Mdownloads / mo
annotated-doc With conditions
PyPI · Software Development · released Jul 2026

Provides a way to document function parameters, class attributes, return types, and variables inline using Python's `Annotated` type hint syntax instead of traditional docstrings.

MITpure Python · 3.9+
456.2Mdownloads / mo
typer Worth it
PyPI · Software Development · released Aug 2026

Typer builds command-line applications from Python functions using type hints, automatically generating help text, argument parsing, and shell completion.

Install it if you are building CLIs in Python.

MITpure Python · 3.10+
369.3Mdownloads / mo
distlib With conditions
PyPI · Software Development · released Jun 2026

Distlib provides low-level packaging utilities for building, distributing, and managing Python software—including metadata handling, version specifiers, wheel support, script installation, and dependency resolution.

permissive licensepure Python
323.3Mdownloads / mo

See also cyseq · typecode-libmagic · extractcode-libarchive · commoncode · extractcode-7z · distro2sbom · reuse · typecode · lib4sbom · flawfinder