Skip to main content

Scan a project

The default endpoint, https://api.scanoss.com, requires an API key. A custom API URL, such as an on-prem deployment, may not require one. See Configuration.

Generate fingerprints only

This uploads nothing and needs no API key:

Refresh an existing inventory

Add or update the vulnerability, licence, crypto, and geoprovenance layers on a result you already have, without re-scanning:

Debug logging

Add -v or --verbose to any command to write structured debug logs to stderr. The logs cover the scan flow, the fingerprinting detail, and each API request with its method, URL, status, and duration. Stdout carries only results, so logs never corrupt --output or piped JSON.

Commands at a glance

Scanning your project and Decoration and enrichment cover each command in full. You can also run scanoss-cli <command> --help.

What’s next

  • Store your API key, proxy, and CA settings once. See Configuration.
  • Choose between raw, SPDX 2.3, and CycloneDX 1.7 output. See Output formats.