Skip to main content
This page has three ways in: the fastest single path to a working evaluation, a modular version of that same path for going deeper on each step, or a direct jump to the specific capability you want to test. If you’re not sure where to start, use the first one.

Start Here: The End-to-End Workflow

The End-to-End Workflow is the fastest way to see SCANOSS working across a full license-compliance lifecycle, in one guide, without jumping between pages. It takes you from an empty repo to:
  • Pre-commit hooks catching undeclared open-source components before code is even committed
  • A GitHub Actions workflow enforcing copyleft and undeclared-component policies on every pull request
  • Dependency-Track managing vulnerabilities and organisation-wide licence policy over time
The End-to-End Workflow covers license compliance and vulnerability monitoring, but not encryption detection. If you also want to evaluate cryptographic algorithm scanning, add Advanced Analysis from the modular path below.
Once you’ve run through it, see Improving Scan Accuracy to reduce false positives and get more accurate results, worth doing early, since it builds directly on the components you just declared.

Prefer to Go Step by Step?

The same ground, broken into four standalone pages, useful if you want to stop and go deeper at any point, revisit one step later, or you specifically want the encryption/vulnerability API evaluation that the End-to-End Workflow doesn’t cover.

Jump to a Topic

Already know what you want to evaluate, without a guided path at all? Go straight to it: