For license information, the strongest matches are aboutcode-org/scancode-toolkit (ScanCode Toolkit is a comprehensive dependency and license scanner), dependencytrack/dependency-track (Dependency-Track is a software composition analysis platform that ingests) and anchore/syft (Syft is a dependency catalog and software bill of). fossology/fossology and google/licenseclassifier round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.
Hand-picked license scanner open-source repositories, ranked by GitHub stars and activity. Compare the top tools and find the best fit.
ScanCode Toolkit is a software composition analysis tool and scanning framework designed to identify open-source licenses and copyright statements in source code and binary files. It functions as an open-source license detector, a dependency vulnerability scanner, and a generator for standardized software bills of materials in SPDX and CycloneDX formats. The project is built as a plugin-based scanning framework, allowing the integration of custom detection logic, specialized analyzers, and modified scanning behaviors at runtime. It distinguishes itself through the ability to produce formal le
ScanCode Toolkit is a comprehensive dependency and license scanner that generates SPDX-compatible software bills of materials, making it a strong fit for your compliance workflow despite missing a native CI/CD integration module.
Dependency-Track is a software composition analysis tool and vulnerability management system designed to track dependencies and supply chain risk. It functions as a platform for ingesting and analyzing CycloneDX software bills of materials to identify known vulnerabilities and license compliance issues within third-party software components. The system distinguishes itself by mirroring external vulnerability databases locally to enable fast offline analysis and using VEX documents to differentiate between technical vulnerabilities and actual contextual risks. It also integrates with identity
Dependency-Track is a software composition analysis platform that ingests SBOMs to track third-party components and surface license compliance issues alongside vulnerability detection, though it operates as a server-based system rather than a direct CLI scanner.
Syft is a software bill of materials generator, container image scanner, and software dependency catalog. It analyzes container images and filesystems to produce comprehensive inventories of installed packages and dependencies in standard formats. Additionally, it serves as a software attestation tool and an SBOM format converter. The project distinguishes itself through the ability to create cryptographically signed attestations for software inventories to ensure provenance and integrity. It also provides the capability to transform software bills of materials between different industry sche
Syft is a dependency catalog and software bill of materials generator that scans filesystems and containers for package inventories, fitting the scanning aspect of license compliance well though policy enforcement is typically handled by its companion tool Grype.
FOSSology is an open source license compliance software system and toolkit. As a toolkit you can run license, copyright and export control scans from the command line. As a system, a database and web ui are provided to give you a compliance workflow. License, copyright and export scanners are tools used in the workflow.
FOSSology is an open-source license compliance system and toolkit that provides scanning and workflow management for codebases, though it approaches dependency scanning differently than modern package-lock analyzers.
Google/licenseclassifier is a library designed to detect and classify software licenses in source code, making it a fitting building block for license compliance workflows despite lacking a full turnkey CLI or policy enforcement engine.
Vuls is an agentless vulnerability scanner and CVE intelligence aggregator. It identifies security flaws in operating systems, containers, and network devices without requiring the installation of permanent software agents on target machines. The project distinguishes itself by cross-referencing software versions against multiple vulnerability databases, security advisories, and known exploit catalogs. It utilizes platform-based enumeration and lockfile analysis to detect vulnerabilities in network hardware, programming libraries, and website plugins. The tool covers a broad range of securit
This tool is a vulnerability scanner rather than a software license compliance scanner, making it a neighbouring security utility rather than a fit for your dependency license management needs.
Harness is an end-to-end developer platform and DevOps orchestration tool designed to automate software build, test, and deployment pipelines. It functions as a CI/CD platform and a source code management system for hosting and managing version-controlled repositories. The platform provides a remote development environment that launches ephemeral, cloud-based coding spaces to ensure standardized setups. It also includes a centralized artifact registry for storing and managing versioned binary packages and container images used in delivery pipelines. The system covers broad capability areas i
Harness is a comprehensive DevOps and CI/CD platform rather than a dedicated software license compliance scanner, though it orchestrates build pipelines where such tools might be integrated.
Kubescape is a security platform for Kubernetes that provides tools for scanning clusters, configurations, and container images against industry compliance and security benchmarks. It functions as a suite of security utilities, including a compliance auditor, a misconfiguration scanner, and a container vulnerability scanner. The project differentiates itself through automated remediation and active enforcement. It can automatically patch operating system vulnerabilities in images and fix security errors within manifest files. It also utilizes an admission controller to block the deployment of
Kubescape is a Kubernetes security and compliance platform focused on cluster configurations and container vulnerabilities rather than a dedicated software license scanner for codebases.
Strix is an automated security research and vulnerability scanning platform that leverages language models to orchestrate complex security analysis tasks. It functions as a comprehensive framework for penetration testing and continuous security integration, allowing users to embed automated vulnerability research directly into development pipelines or execute it within isolated, containerized environments. The platform distinguishes itself through a multi-agent orchestration engine that coordinates specialized autonomous agents to perform parallel security assessments. By integrating LLM-agno
Strix is an automated security research and vulnerability scanning platform driven by language models, which belongs to the cybersecurity and penetration testing domain rather than software license compliance.
AboutLibraries is an open-source license compliance tool designed to collect, validate, and display third-party library licenses within software projects. It functions as a system for gathering dependency metadata at compile time and validating those libraries against a list of approved licenses to ensure legal compliance. The project provides a license validation engine that can enforce compliance by halting the build process when unauthorized licenses are detected. It also includes a set of visual components for rendering dependency and funding information within a user interface for third-
AboutLibraries is primarily an Android and Kotlin Multiplatform UI library for displaying dependency attribution and about pages rather than a general-purpose codebase license scanner with CI/CD integration.
Wazuh is an integrated security platform that combines endpoint detection and response, security information and event management, and cloud workload protection. It functions as a centralized system for collecting telemetry, aggregating logs, and correlating events across distributed infrastructure to maintain security and integrity. The platform distinguishes itself through its active response orchestration, which allows for the automated execution of scripts on remote endpoints to neutralize threats in real time. It provides deep visibility into system activity through file integrity monito
Wazuh is a security and compliance platform for threat detection and infrastructure monitoring, which is a different category from a software license scanner for codebases and dependencies.
| Repository | Stars | Language | License | Last push |
|---|---|---|---|---|
| aboutcode-org/scancode-toolkit | 2.6K | Python | NOASSERTION | |
| dependencytrack/dependency-track | 3.6K | Java | apache-2.0 | |
| anchore/syft | 8.4K | Go | apache-2.0 | |
| fossology/fossology | 1K | HTML | GPL-2.0 | |
| google/licenseclassifier | 0 | — | — | — |
| future-architect/vuls | 12.2K | Go | GPL-3.0 | |
| harness/harness | 36.9K | Go | Apache-2.0 | |
| armosec/kubescape | 11.5K | Go | Apache-2.0 | |
| usestrix/strix | 20.1K | Python | apache-2.0 | |
| mikepenz/aboutlibraries | 4.2K | Kotlin | apache-2.0 |