Skip to main content
SCANOSS does not maintain plugins for individual CI platforms. Recipes take their place. Each recipe is a complete workflow built from the standalone tools and written as plain shell commands, with an explanation of every step and its output. Because a recipe is plain shell commands, it runs anywhere you can run a shell: a CI job, a Git hook, a scheduled job, or your terminal. Where a recipe shows CI configuration, it is only an example of how to call the same script.
If you would rather not build and maintain this yourself, Earnie provides policies, merge gates, triage, dashboards, and evidence out of the box.

Available recipes

Scan every pull request in CI

Scan each pull request and fail it when open source appears that you have not approved.

Fail the build on a disallowed licence or a known vulnerability

A small policy script over the scan result, with a deny-list of licences and a severity threshold.

Approve components with scanoss.json

Declare known components once, so they stop failing your checks.

Local pre-commit check

Scan only the staged files before each commit.

Generate an SBOM for each release

One scan, then SPDX and CycloneDX files to publish with the release.

Keep an existing SBOM current

A weekly vulnerability and licence refresh with enrich, without re-scanning.

Build a cryptographic inventory (CBOM)

Inventory cryptography with Crypto Finder for post-quantum readiness.

Fingerprint-only scanning for restricted environments

Fingerprint offline, then scan the fingerprints from a connected machine.

Before you use a recipe

Every recipe assumes:
  • scanoss-cli is installed and on your PATH (see Quickstart). The cryptography recipe needs Crypto Finder instead.
  • SCANOSS_API_KEY is set in the environment. In CI, inject it from your secret store. See API keys and authentication.
  • jq is installed. The tools write JSON, and the recipes use jq to read it.
  • Bash runs the scripts. They start with set -euo pipefail, so any failing command stops the script with a non-zero exit code.

How the tools signal failure

Recipes that fail a build rely on these exit codes: scanoss-cli has no option to fail on findings. The recipes add a short jq check on its JSON output for that, and exit with code 2 when the check fails. This keeps “the tool failed” (1) apart from “the policy failed” (2) in your pipeline logs.

Pin your versions

In CI, install a fixed version of each tool rather than latest, so a new release cannot change your results without a code change. The recipes use scanoss-cli v0.9.0. Check the scanoss-cli releases and Crypto Finder releases for newer versions.