> ## Documentation Index
> Fetch the complete documentation index at: https://docs.scanoss.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Recipes

> Copy-pasteable, explained workflows built from scanoss-cli and Crypto Finder. Each one runs as plain shell commands in any CI system, Git hook, or terminal.

SCANOSS does not maintain plugins for individual CI platforms. Recipes take their place. Each
recipe is a complete workflow built from the standalone tools and written as plain shell commands,
with an explanation of every step and its output.

Because a recipe is plain shell commands, it runs anywhere you can run a shell: a CI job, a Git
hook, a scheduled job, or your terminal. Where a recipe shows CI configuration, it is only an
example of how to call the same script.

<Note>
  If you would rather not build and maintain this yourself, [Earnie](/en/latest/earnie/introduction)
  provides policies, merge gates, triage, dashboards, and evidence out of the box.
</Note>

## Available recipes

<CardGroup cols={2}>
  <Card title="Scan every pull request in CI" href="/en/latest/developer-tools/recipes/scan-pull-requests">
    Scan each pull request and fail it when open source appears that you have not approved.
  </Card>

  <Card title="Fail the build on a disallowed licence or a known vulnerability" href="/en/latest/developer-tools/recipes/licence-and-vulnerability-gate">
    A small policy script over the scan result, with a deny-list of licences and a severity threshold.
  </Card>

  <Card title="Approve components with scanoss.json" href="/en/latest/developer-tools/recipes/approve-components-bom-rules">
    Declare known components once, so they stop failing your checks.
  </Card>

  <Card title="Local pre-commit check" href="/en/latest/developer-tools/recipes/pre-commit-check">
    Scan only the staged files before each commit.
  </Card>

  <Card title="Generate an SBOM for each release" href="/en/latest/developer-tools/recipes/release-sbom">
    One scan, then SPDX and CycloneDX files to publish with the release.
  </Card>

  <Card title="Keep an existing SBOM current" href="/en/latest/developer-tools/recipes/refresh-sbom-with-enrich">
    A weekly vulnerability and licence refresh with `enrich`, without re-scanning.
  </Card>

  <Card title="Build a cryptographic inventory (CBOM)" href="/en/latest/developer-tools/recipes/crypto-inventory-cbom">
    Inventory cryptography with Crypto Finder for post-quantum readiness.
  </Card>

  <Card title="Fingerprint-only scanning for restricted environments" href="/en/latest/developer-tools/recipes/fingerprint-only-scanning">
    Fingerprint offline, then scan the fingerprints from a connected machine.
  </Card>
</CardGroup>

## Before you use a recipe

Every recipe assumes:

* scanoss-cli is installed and on your `PATH` (see [Quickstart](/en/latest/developer-tools/quickstart)).
  The cryptography recipe needs Crypto Finder instead.
* `SCANOSS_API_KEY` is set in the environment. In CI, inject it from your secret store. See
  [API keys and authentication](/en/latest/developer-tools/authentication).
* `jq` is installed. The tools write JSON, and the recipes use `jq` to read it.
* Bash runs the scripts. They start with `set -euo pipefail`, so any failing command stops
  the script with a non-zero exit code.

## How the tools signal failure

Recipes that fail a build rely on these exit codes:

| Tool | Exit `0` | Non-zero |
| - | - | - |
| scanoss-cli | The command completed, **whatever it found** | `1`: the command failed (no API key, API unreachable, invalid flag, output not writable, and so on) |
| Crypto Finder | The scan completed | `1`: the scan failed, or it detected findings and `--fail-on-findings` was set |

scanoss-cli has no option to fail on findings. The recipes add a short `jq` check on its JSON
output for that, and exit with code `2` when the check fails. This keeps "the tool failed" (`1`)
apart from "the policy failed" (`2`) in your pipeline logs.

## Pin your versions

In CI, install a fixed version of each tool rather than `latest`, so a new release cannot change
your results without a code change. The recipes use scanoss-cli `v0.9.0`. Check the
[scanoss-cli releases](https://github.com/scanoss/scanoss.go/releases) and
[Crypto Finder releases](https://github.com/scanoss/crypto-finder/releases) for newer versions.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.