If you would rather not build and maintain this yourself, Earnie
provides policies, merge gates, triage, dashboards, and evidence out of the box.
Available recipes
Scan every pull request in CI
Scan each pull request and fail it when open source appears that you have not approved.
Fail the build on a disallowed licence or a known vulnerability
A small policy script over the scan result, with a deny-list of licences and a severity threshold.
Approve components with scanoss.json
Declare known components once, so they stop failing your checks.
Local pre-commit check
Scan only the staged files before each commit.
Generate an SBOM for each release
One scan, then SPDX and CycloneDX files to publish with the release.
Keep an existing SBOM current
A weekly vulnerability and licence refresh with
enrich, without re-scanning.Build a cryptographic inventory (CBOM)
Inventory cryptography with Crypto Finder for post-quantum readiness.
Fingerprint-only scanning for restricted environments
Fingerprint offline, then scan the fingerprints from a connected machine.
Before you use a recipe
Every recipe assumes:- scanoss-cli is installed and on your
PATH(see Quickstart). The cryptography recipe needs Crypto Finder instead. SCANOSS_API_KEYis set in the environment. In CI, inject it from your secret store. See API keys and authentication.jqis installed. The tools write JSON, and the recipes usejqto read it.- Bash runs the scripts. They start with
set -euo pipefail, so any failing command stops the script with a non-zero exit code.
How the tools signal failure
Recipes that fail a build rely on these exit codes:
scanoss-cli has no option to fail on findings. The recipes add a short
jq check on its JSON
output for that, and exit with code 2 when the check fails. This keeps “the tool failed” (1)
apart from “the policy failed” (2) in your pipeline logs.
Pin your versions
In CI, install a fixed version of each tool rather thanlatest, so a new release cannot change
your results without a code change. The recipes use scanoss-cli v0.9.0. Check the
scanoss-cli releases and
Crypto Finder releases for newer versions.