Scanning
scan fingerprints the target, uploads the WFP in blocks to POST /v3/wfp/scan, and polls
GET /v3/wfp/scan/<scan-id> until the scan completes. It prints the scan id as soon as the upload
finishes, so you can resume an interrupted scan with results.
Tuning throughput
Keeping the generated WFP
wfp
command when you need byte-reproducible output to diff or hash.
Scanning a pre-generated WFP
Resuming a scan
results works after a Ctrl+C because the uploaded WFP is resumable. A resumed scan applies the
same rules as a direct one, so results accepts --settings, -i/-n, --ranking-threshold, --include
(vulns, licenses, crypto, geo), -f, --format and --poll-interval, plus the
API flags.
Flags reference
The API flags work on every command that reaches the API:scan, scan wfp, results,
enrich, dependencies, and the decoration commands.
scan and scan wfp share the scan flags.
The fingerprinting flags work only on
scan <path> and the standalone
wfp command. scan wfp receives a WFP that is already assembled, so it
doesn’t accept them, and passing --skip-headers or --skip-headers-limit to it is an error.
Fingerprinting only
wfp generates fingerprints without contacting the API, so it needs no key:
-o, --output and --settings. Unlike scan --save-wfp, its output is byte-reproducible, so use it when you need to diff or hash a WFP.
Skipping files
Before scanning, the CLI filters out build directories, vendored dependencies, generated and binary files, model weights (.safetensors, .gguf, .onnx, .pt, .bin), and oversized files.
There is no minimum file size by default. Set one with --min-size:
--all-extensions turns off the built-in file rules, which match extensions, name endings, and
exact names. --all-folders turns off the directory rules. They are separate switches because
someone who wants every folder scanned rarely wants every binary fingerprinted too. --all-hidden
includes dotted entries, .git among them.
To set skip rules for the whole project, use scanoss.json:
scanoss.json together. --min-size and --max-size apply to every
file, while a skip.sizes rule applies only to the files its patterns match.
BOM rules
Configure a Bill of Materials inscanoss.json. The CLI finds the file in the target
automatically, or you can pass its path with --settings:
bom.ignore(aliasbom.exclude) drops the components it names from each file’s matches.bom.identify(aliasbom.include) marks the components it names as"identified": trueand moves them to the front of their file’s matches.--ranking-thresholddrops matches whose component ranks worse than the threshold.bom.removeneutralizes whole files.bom.replacere-points the survivors at theirreplace_withcomponent.
-
Scoping. An entry may be scoped by
purl, bypath, or both. Where several entries cover the same file, the most specific one wins: -
Canonical PURLs only.
bom.ignoreandbom.identifymatch a component’s canonical PURL, not its aliases.bom.removeandbom.replacedo match aliases. -
bom.identifywins. It protects its PURLs from every filter in this list:bom.ignore,bom.remove, and the ranking threshold. -
Ranking threshold. Rank is how well a component explains a match; lower is stronger, and
real ranks run from 1 to 9. Matches with no rank, or the engine’s
999“no ranking information” sentinel, are never filtered. -
Where
identifiedshows up. The CLI writes the flag on each matched file’s evidence, and on the component as a summary, because apath-scoped rule claims a component only in the files it covers. CycloneDX output carries the component-level flag as ascanoss:identifiedproperty. Onlyrawoutput has the per-file detail.
-i, --identify <file> and -n, --ignore <file> on the command line add unscoped entries to the
same rules, and you can combine them with --settings. Each takes a file, which can be a SCANOSS
component list ({"components":[{"purl":"..."}]}), CycloneDX, SPDX, or this CLI’s own raw
output. The CLI detects the type from the content.
Snippet settings in scanoss.json
scanoss.json can also carry fingerprinting and filtering settings:
ranking_threshold accepts values from -1 to 10, where -1 and 0 both mean off. The CLI
clamps out-of-range values and prints a warning. Other file_snippet keys, such as
min_snippet_hits, ranking_enabled, and honour_file_exts, tune the matching engine. This CLI
ignores them because it doesn’t forward scan settings to the server.
Output layers
By default a scan reports only the components it detected.--include adds extra layers, which
cover both detected and declared components:
--format can’t represent a layer, the CLI doesn’t gather that layer and prints a
message up front. raw renders every layer, cyclonedx drops crypto and geo, and spdx drops
vulns, crypto, and geo.