Skip to main content
This guide installs scanoss-cli, scans a project, and turns the result into a CycloneDX SBOM. You need:
  • a SCANOSS API key (see API keys and authentication)
  • a project directory to scan
  • jq, to read the JSON output (optional, but used in the examples)
1

Install scanoss-cli

Download the prebuilt binary for your platform from the releases page and put it on your PATH. For Linux on x86-64:
Each release has archives for Linux (amd64, arm64, armv7), macOS (darwin-amd64, darwin-arm64), and Windows (windows-amd64.zip, windows-arm64.zip). If you have Go 1.25 or later, you can install with Go instead:
For Docker and other options, see Installation.
2

Provide your API key

To keep the key between shell sessions, store it once with scanoss-cli config set api-key "<your-key>" instead.
3

Scan the project

The CLI fingerprints every file locally, uploads only the fingerprints, and waits for the result. Progress and the scan ID go to stderr. The result goes to results.json.--include adds optional data to the result. licenses adds the licences of each component, and vulns adds known vulnerabilities. Add deps to also list the dependencies declared in your manifest files.
4

Read the result

results.json is the SCANOSS raw inventory. This is an abbreviated example of its shape:
Summarise it with jq:
An empty components list means no open source was matched.
5

Generate an SBOM

Convert the inventory you already have. The conversion runs offline and does not scan again:
CycloneDX 1.7 keeps the vulnerabilities. SPDX 2.3 has no vulnerability model, so the CLI leaves them out of the SPDX file and warns you.

Exit codes

scanoss-cli exits 0 when a command completes, whatever it found, and 1 when the command fails. A missing API key, an unreachable API, an invalid flag, or an output file that cannot be written all cause exit code 1. Findings never change the exit code. To fail a build on findings, check the JSON output, as the Recipes show.

Next steps

  • Recipes show how to scan every pull request, gate on licences and vulnerabilities, publish release SBOMs, and more.
  • Scanning your project covers every scan flag, file skipping, and BOM rules.
  • Output formats describes the raw, SPDX, and CycloneDX formats in detail.