Skip to main content
FOSSA Logo

Summer 2026 Product Updates: Enhanced Reports

July 20, 2026 · 4 min read·Andy Drukarev
Summer 2026 Product Updates: Enhanced Reports

Reports have long been one of the most important and utilized parts of the FOSSA product. A licensing report satisfies open source license attribution obligations. An SBOM is a required part of regulations like the EU CRA, DORA, and PCI DSS; it's also increasingly the first thing a customer or partner asks for before signing a deal. A remediation guidance report gives engineering leaders a prioritized, low-effort path to closing out vulnerabilities.

Given the mission-critical nature of reports to our customers, FOSSA’s product and engineering teams have made continuous improvements to reporting functionality over the years. That includes a series of upgrades in recent months, which we’ll discuss below.

What's New in Reports

Saved Report Settings

You can now save a report configuration as a named preset and set it as the default for a project or release group. This is particularly useful for scenarios like producing an SBOM to fulfill a specific regulation with defined technical requirements.

If your organization wants every developer generating the same standardized report, you no longer have to walk each person through the same filters by hand. Simply set the default once, and it applies out of the box across the board. Additionally, you can have different presets for different use cases; for example, there could be a preset for an internal report with a set of requirements, a separate preset for an external agency, a separate preset for a manufacturing partner, and so on. Saved presets can also be renamed, updated, or swapped out as your requirements change.

Updated Standard Report Types

There are two types of report experiences in FOSSA:

  1. A “Standard” flow, which is what’s available as a pre-set option out of the box
  2. A “Custom” flow, where you have full control over every element of the report; you can also build customizations on top of our out-of-the-box configurations

In the interest of best reflecting the expertise we’ve gleaned from our advisors and customers, we’ve made several adjustments to the new “Standard” report types to provide what we believe is the best default report for most organizations, available on every plan. If you need finer control, the “Custom” flow still gives you full command over every filter, content option, and data point.

Support for Larger, More Complex Projects

Although FOSSA’s previous reporting infrastructure effectively accommodated the vast majority of our customers’ needs, we would periodically hear of technical roadblocks with larger and more complex projects. We’ve made several architecture changes to ensure efficient report creation for even the most sophisticated projects with far larger dependency trees and more complex release group structures.

Cleaner Attribution Formatting

Licensing reports no longer repeat the full text of the same license over and over for every dependency that uses it. License text is consolidated, so attribution documents are shorter, cleaner, and easier to actually read.

How to Create Reports in FOSSA

Full documentation is available on our docs site, but here's a quick refresher with instructions on each report type.

  • SBOM: From a project or release group, go to Reports > SBOM, choose Standard or Custom, and pick a format: SPDX (tag-value or JSON) or CycloneDX (JSON or XML). CycloneDX exports can embed VDR and VEX vulnerability statements.
  • Licensing (Attribution) Report: Go to Reports > Licensing, choose a flow, and select an export format: HTML, PDF, CSV, Markdown, or plain text. This is the document you ship to satisfy attribution obligations, covering dependency summaries, licenses, copyrights, and license text.
  • Global Report: From the organization-wide Reports dashboard, generate a Global Package Report Bundle, an Audit/Due Diligence report, or a Global Issue CSV export, each aggregating data across every project in your org rather than one at a time.
  • Remediation Guidance Report: From a project or release group's Reports > Remediation Guidance, generate a PDF, HTML, or JSON report that organizes fixes into Quick Wins, High Priority, Low Priority, Outdated, and Malicious Dependency categories. This provides actionable insights into the fastest path to reducing risk with the least engineering effort.

You can also set defaults, logos, descriptions, and saved filter presets for any project or release group under Report Settings.

Learn More About FOSSA Reports

License compliance, SBOM mandates, and exec-level risk visibility aren't going away. Our latest round of reporting enhancements gives customers more tools to help generate the most accurate, relevant, and actionable reports as efficiently as possible.

If you have any questions about our new reporting capabilities, please reach out to your customer success contact. Or, if you’re not currently a FOSSA customer, book a demo to learn more.

Subscribe to our newsletter

Get the latest insights on open source license compliance and security delivered to your inbox.