- a SCANOSS API key (see API keys and authentication)
- a project directory to scan
jq, to read the JSON output (optional, but used in the examples)
1
Install scanoss-cli
Download the prebuilt binary for your platform from the
releases page and put it on your Each release has archives for Linux (For Docker and other options, see Installation.
PATH.
For Linux on x86-64:amd64, arm64, armv7), macOS (darwin-amd64,
darwin-arm64), and Windows (windows-amd64.zip, windows-arm64.zip). If you have Go 1.25
or later, you can install with Go instead:2
Provide your API key
scanoss-cli config set api-key "<your-key>" instead.3
Scan the project
results.json.--include adds optional data to the result. licenses adds the licences of each component,
and vulns adds known vulnerabilities. Add deps to also list the dependencies declared in
your manifest files.4
Read the result
results.json is the SCANOSS raw inventory. This is an abbreviated example of its shape:Summarise it with
jq:components list means no open source was matched.5
Generate an SBOM
Convert the inventory you already have. The conversion runs offline and does not scan again:CycloneDX 1.7 keeps the vulnerabilities. SPDX 2.3 has no vulnerability model, so the CLI leaves
them out of the SPDX file and warns you.
Exit codes
scanoss-cli exits 0 when a command completes, whatever it found, and 1 when the command
fails. A missing API key, an unreachable API, an invalid flag, or an output file that cannot be
written all cause exit code 1. Findings never change the exit code. To fail a build on findings, check the
JSON output, as the Recipes show.
Next steps
- Recipes show how to scan every pull request, gate on licences and vulnerabilities, publish release SBOMs, and more.
- Scanning your project covers every scan flag, file skipping, and BOM rules.
- Output formats describes the raw, SPDX, and CycloneDX formats in detail.