scanoss
Simple Python library to leverage the SCANOSS APIs
Decision gist · record as of 2026-08-14
Yes. Scanoss is actively maintained, has low install friction, carries a permissive MIT license, and solves a real problem in software supply chain security and compliance. It integrates easily into Python projects or runs standalone. No known vulnerabilities. Suitable for teams needing open-source component tracking and license auditing.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.9 or higher.
- Optional: install scanoss_winnowing or scancode-toolkit for enhanced fingerprinting and dependency decoration.
- Low install friction with a pure-Python wheel distribution.
License · maintenance · safety
MIT (permissive) — MIT license permits unrestricted use, modification, and distribution with minimal restrictions—suitable for both open-source and commercial projects.
last release 2026-07-21 (24 days) · last repo commit 2026-07-27 · 41 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 102,123 downloads/mo, #12,889 on PyPI
Alternatives
Verify before relying
pip install scanoss
from scanoss.scanner import Scanner
scanner = Scanner()
scanner.scan_folder('.')- Accuracy and completeness of component matching against the SCANOSS knowledge base
- Performance characteristics when scanning large codebases
- API rate limits and availability guarantees for the default OSS KB endpoint
What it is and what it does
Scanoss is a Python library that scans source code to identify open-source components, their licenses, and known vulnerabilities by fingerprinting files and matching them against the SCANOSS open-source knowledge base. It works both as a command-line tool and as a library you can import into your own Python projects.
The package handles the full workflow of code analysis: fingerprinting source files, submitting them to the SCANOSS API (defaulting to the free OSS KB at api.osskb.org), and parsing results to identify components and their metadata. It supports custom API endpoints and keys, optional fast fingerprinting via an external winnowing package, and dependency decoration when scancode-toolkit is installed. The 16 runtime dependencies handle HTTP requests, protocol buffers for API communication, file introspection, and SBOM generation.
Use it for
- Scan a codebase to generate a software bill of materials (SBOM) identifying all open-source components
- Check source code for known security vulnerabilities in dependencies before deployment
- Audit license compliance by identifying all open-source licenses present in a project
- Fingerprint and match code fragments to detect reused or derivative open-source software
- Integrate component detection into a CI/CD pipeline to block builds with unacceptable licenses or vulnerabilities
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
Scanoss is actively maintained, has low install friction, carries a permissive MIT license, and solves a real problem in software supply chain security and compliance. It integrates easily into Python projects or runs standalone. No known vulnerabilities. Suitable for teams needing open-source component tracking and license auditing.
Install
scanoss on PyPI
Before you install
Low install friction with a pure-Python wheel distribution. Active maintenance with a recent release (24 days old) and ongoing repository activity. Requires Python 3.9 or higher.
Requires Python 3.9 or higher. Optional: install scanoss_winnowing or scancode-toolkit for enhanced fingerprinting and dependency decoration.
License in practice
MIT license permits unrestricted use, modification, and distribution with minimal restrictions—suitable for both open-source and commercial projects.
Quickstart
pip install scanoss
from scanoss.scanner import Scanner
scanner = Scanner()
scanner.scan_folder('.')
Verify before relying
- Accuracy and completeness of component matching against the SCANOSS knowledge base
- Performance characteristics when scanning large codebases
- API rate limits and availability guarantees for the default OSS KB endpoint
Package facts
| License | MIT permissive |
| Python support | Supports the current Python release >=3.9 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 16 packagesrequestscrc32cbinaryornotprogressgrpcioprotobufprotoc-gen-openapiv2pypacpyOpenSSLgoogle-api-coreimportlib_resourcespackageurl-pythonpathspecjsonschemacrccyclonedx-python-lib |
| Maintenance | Actively maintained 24 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 102,123 / month, #12,889 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableLicense :: OSI Approved :: MIT LicenseOperating System :: OS IndependentProgramming Language :: Python :: 3 |
Evidence: scanoss-1.54.2-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “source code scanning”
- scanossScanoss provides a Python library and CLI tool to fingerprint source…
- scancode-toolkitScanCode Toolkit detects licenses, copyrights, package metadata, and…
- guarddogGuardDog is a CLI tool that scans PyPI, npm, Go, Rust, RubyGems,…
Give your agent the search over MCP, or paste the wish link into any chat.
More Quality Assurance packages
Coverage.py measures which lines of Python code are executed during test runs, reporting coverage percentages and identifying untested code paths.
Install it if you want to measure test completeness or enforce coverage thresholds in your project.
Ruff is a Python linter and code formatter written in Rust that combines linting, formatting, and code fixing into a single tool, replacing Flake8, Black, isort, and related utilities.
Pexpect spawns and controls interactive console applications by sending input and matching output patterns, automating tasks that would otherwise require manual interaction.
Black reformats Python source code to a consistent style by parsing entire files and rewriting them according to an opinionated, deterministic set of rules, eliminating manual formatting decisions.
pytest-xdist distributes pytest tests across multiple CPU cores or machines to speed up test execution, with the simplest usage being `pytest -n auto` to spawn workers equal to available CPUs.
Install it if your test suite takes long enough that parallelization would save meaningful time.
Validates AWS CloudFormation templates in YAML or JSON format against resource provider schemas and best practices, checking property values and configuration correctness.
Install it if you work with CloudFormation templates.
See also trufflehog3 · bbot · flawfinder · picklescan · cycode · kingfisher-bin · uv-secure · safety · scancode-toolkit · cyseq