Skip to main content
SCANOSS gives you two ways to answer the same questions: what open source is in this code, under which licences, with which known vulnerabilities, and which cryptography it uses. Both ways use the same SCANOSS Knowledge Base. The difference is how much of the work around the results SCANOSS does for you.

Option 1: Earnie, ready to use

Earnie is SCANOSS’s governance platform. Choose it if you want SCANOSS to run the whole workflow for you:
  • policies that you define once and apply to every repository
  • a merge gate on every pull request
  • a review workspace to triage findings and record decisions
  • dashboards across all your projects
  • exportable evidence for customers and auditors
You connect your repositories, and Earnie runs the scans, applies your policies, and records each decision. You write no pipeline code.

Go to Earnie

Policies, merge gates, triage, dashboards, and evidence in one platform.

Option 2: Standalone tools, build your own pipeline

Choose the standalone tools if you already have a pipeline, a results store, or a review process, and you want SCANOSS data inside it. You run the tools, you keep the output, and you decide what fails a build. SCANOSS does not maintain integrations for specific CI platforms. Instead, we publish Recipes. Each Recipe is a complete workflow written in plain shell commands, with an explanation of every step. Recipes run in any CI system, in a Git hook, or on a laptop.
scanoss-cli uses the SCANOSS v3 API and does not work with OSSKB.org. If you depend on OSSKB.org, use SCANOSS-PY.

Which one fits?

Where to start

1

Get an API key

The hosted SCANOSS API at https://api.scanoss.com requires an API key. See API keys and authentication.
2

Run your first scan

Install scanoss-cli, scan a project, and generate an SBOM in about five minutes. See Quickstart.
3

Pick a Recipe

Copy a complete workflow into your pipeline. See Recipes.

Running SCANOSS in your own infrastructure

If you need the SCANOSS Knowledge Base inside your own network instead of calling the hosted API, see the Knowledge Base and deployment pages in this section. You then set a custom API URL so both tools send requests to your deployment. See Use a custom API URL.