For license utilities, the strongest matches are aboutcode-org/scancode-toolkit (ScanCode Toolkit is a comprehensive software composition analysis tool), mikepenz/aboutlibraries (AboutLibraries is a license compliance tool tailored for Kotlin) and dependencytrack/dependency-track (Dependency-Track is an enterprise software composition analysis platform that). anchore/syft and fossology/fossology round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.
Hand-picked open-source license compliance tools for developers. Compare the top repositories by stars, features, and activity to find the right fit.
ScanCode Toolkit is a software composition analysis tool and scanning framework designed to identify open-source licenses and copyright statements in source code and binary files. It functions as an open-source license detector, a dependency vulnerability scanner, and a generator for standardized software bills of materials in SPDX and CycloneDX formats. The project is built as a plugin-based scanning framework, allowing the integration of custom detection logic, specialized analyzers, and modified scanning behaviors at runtime. It distinguishes itself through the ability to produce formal le
ScanCode Toolkit is a comprehensive software composition analysis tool that scans codebases for open-source licenses, generates SPDX bills of materials, and supports compliance reporting.
AboutLibraries is an open-source license compliance tool designed to collect, validate, and display third-party library licenses within software projects. It functions as a system for gathering dependency metadata at compile time and validating those libraries against a list of approved licenses to ensure legal compliance. The project provides a license validation engine that can enforce compliance by halting the build process when unauthorized licenses are detected. It also includes a set of visual components for rendering dependency and funding information within a user interface for third-
AboutLibraries is a license compliance tool tailored for Kotlin and mobile projects that extracts dependency metadata and validates licenses at compile time, fitting the category well despite being platform-focused.
Dependency-Track is a software composition analysis tool and vulnerability management system designed to track dependencies and supply chain risk. It functions as a platform for ingesting and analyzing CycloneDX software bills of materials to identify known vulnerabilities and license compliance issues within third-party software components. The system distinguishes itself by mirroring external vulnerability databases locally to enable fast offline analysis and using VEX documents to differentiate between technical vulnerabilities and actual contextual risks. It also integrates with identity
Dependency-Track is an enterprise software composition analysis platform that ingests bills of materials to track third-party dependencies, monitor vulnerabilities, and handle license compliance resolution, making it a strong tool for open-source governance.
Syft is a software bill of materials generator, container image scanner, and software dependency catalog. It analyzes container images and filesystems to produce comprehensive inventories of installed packages and dependencies in standard formats. Additionally, it serves as a software attestation tool and an SBOM format converter. The project distinguishes itself through the ability to create cryptographically signed attestations for software inventories to ensure provenance and integrity. It also provides the capability to transform software bills of materials between different industry sche
Syft is a software bill of materials generator and dependency catalog that creates standard inventories from container images and filesystems, fitting the core SBOM and dependency scanning requirements well while focusing primarily on inventory generation rather than full license compliance management.
FOSSology is an open source license compliance software system and toolkit. As a toolkit you can run license, copyright and export control scans from the command line. As a system, a database and web ui are provided to give you a compliance workflow. License, copyright and export scanners are tools used in the workflow.
FOSSology is a comprehensive open source license compliance system and toolkit featuring dependency license scanning, workflow management, and reporting to support software governance and compliance audits.
The software bill of materials tool is a command-line application that scans source directories and container images to produce standards-compliant inventory manifests of project dependencies and build components. It provides utilities for generating, validating, and aggregating manifest files, alongside features for checking files against industry specifications and target build directories. The application integrates directly into continuous integration pipelines to automate security workflows during the build process. It features a container image inspection engine that extracts container
Microsoft sbom-tool is a utility designed to generate Software Bill of Materials (SBOM) and support compliance reporting for projects and codebases.
Licensed is a command-line utility for auditing open-source dependencies and validating compliance policies across multi-language packages. Written in Ruby, the tool scans project dependencies to identify external libraries, discovers associated license files and legal notices across directory hierarchies, and caches metadata directly within the repository for historical review. The tool evaluates detected dependencies against defined compliance rules that handle accepted licenses, ignored lists, and configuration settings specified in YAML or JSON formats. It supports custom dependency sour
Licensed is a Ruby gem that caches and verifies dependency licenses to help manage open source compliance, though it lacks broader SBOM generation and reporting features.
govendor is a toolset for Go dependency management that enables the replication of external packages into a local directory to ensure reproducible builds without requiring active network access. It functions as a dependency vendor tool and version manager, fetching specific git revisions, tags, or branches of remote packages. The project includes a dependency auditor to identify missing, modified, or outdated packages compared to their remote sources. It also provides a license extraction utility that discovers and lists the legal licenses associated with project import paths and dependencies
It is a Go dependency management and vendoring tool with a license extraction utility, but it lacks the comprehensive software bill of materials and governance features needed for a full compliance platform.
GLWTPL is a standardized legal framework and template system for releasing software into the public domain. Its primary purpose is to provide a consistent method for stripping authors of all responsibility and liability regarding software quality, maintenance, or warranties. The project utilizes a multilingual license framework to ensure that disclaimers of responsibility are understood across different languages and regions. It achieves this through a system of translated legal terms and localized license templates. The system functions by injecting project metadata into predefined disclaim
This repository is a humorous boilerplate legal framework and template for public domain disclaimers rather than a software tool for scanning dependencies or generating SPDX-compliant compliance reports.
Retire.js is a JavaScript vulnerability scanner and dependency security analyzer. It identifies outdated or insecure JavaScript libraries with known security flaws within web applications and local projects. The tool functions as a web security auditing utility that can be used during penetration testing to detect vulnerable scripts on live websites. It supports the generation of Software Bills of Materials using the CycloneDX format to document project dependencies. The system utilizes signature-based library detection and pattern-matching to map identified versions against a JSON-based sec
Retire.js is a vulnerability and security scanner rather than a software license management tool, meaning it detects insecure dependencies instead of auditing or generating licenses.
SecurityAdvisories is a software composition analysis tool and PHP security advisory database used to audit project dependencies against known security flaws and CVEs. It functions as a vulnerability scanner for PHP projects to identify and manage risky third-party libraries. The project implements a system for detecting and blocking vulnerable dependencies during the software development lifecycle. It prevents the installation of software packages with known security flaws by maintaining an exclusion list of forbidden versions. The tool integrates with the PHP package manager to intercept d
This is a software composition analysis tool focused specifically on security vulnerabilities and CVEs rather than software license compliance or SBOM generation.
| Repository | Stars | Language | License | Last push |
|---|---|---|---|---|
| aboutcode-org/scancode-toolkit | 2.6K | Python | NOASSERTION | |
| mikepenz/aboutlibraries | 4.2K | Kotlin | apache-2.0 | |
| dependencytrack/dependency-track | 3.6K | Java | apache-2.0 | |
| anchore/syft | 8.4K | Go | apache-2.0 | |
| fossology/fossology | 1K | HTML | GPL-2.0 | |
| microsoft/sbom-tool | 2K | C# | mit | |
| licensee/licensed | 1K | Ruby | MIT | |
| kardianos/govendor | 4.9K | Go | BSD-3-Clause | |
| me-shaon/glwtpl | 5K | — | NOASSERTION | |
| retirejs/retire.js | 4.1K | JavaScript | Apache-2.0 |