---
title: "FOSSA Scan | Universal Software Supply Chain Scanner"
description: "Automatically scan open source dependencies, licenses, and security vulnerabilities in your codebase with FOSSA Scan."
canonical_url: "https://fossa.com/products/scan/"
markdown_url: "https://fossa.com/products/scan.md"
language: "en"
author: "FOSSA"
organization: "FOSSA"
---

# FOSSA Scan | Universal Software Supply Chain Scanner

> Automatically scan open source dependencies, licenses, and security vulnerabilities in your codebase with FOSSA Scan.

scan

Universal Scanner Platform

## Scan Your Entire Software Supply Chain

FOSSA's universal scanner identifies dependencies, vulnerabilities, and license issues across your entire SDLC — from code to containers and beyond.

Packages

Containers

SBOMs

Binaries

Snippets

SCAN

### One Scanner to Rule Them All

Effortlessly track 3rd party artifacts across your entire SDLC with a consolidated, scalable, universal scanner

#### Identify All Dependencies

Fast, universal open source dependency scanning with comprehensive license and vulnerability detection.

[Fast, universal dependency (OSS) analysis for 30+ languages](https://docs.fossa.com/docs/supported-languages)

[Deep, embedded detection for open source and proprietary licenses](https://fossa.com/solutions/oss-license-compliance.md)

[Identify CVEs with advanced filtering and prioritization](https://fossa.com/solutions/code-security.md)

[Zero-configuration, get started instantly (in the cloud or locally with fossa-cli)](https://app.fossa.com/auth/register)

Quick Import

Automatically analyze from code host for easy initial results.

Open source management powered by FOSSA, Inc. © 2025

POLICY

### Enforce Robust, Scalable Policies

Set enterprise-wide standards with our flexible, scalable policy engine to automate license, security and quality standards at any size.

#### Enforce Open Source Standards

Implement scalable policies for compliance, security, and quality across your organization.

[Starter policies for early programs on compliance, security and quality](https://fossa.com/solutions/)

Scalable and customizable for mature programs

Integrated at the left — into CICD, PRs

Policies/Standard Bundle Distribution

Starter policy template for most types of apps and software bundles.

5

#### Deny

AGPL

Strong copyleft license with strict source code distribution requirements.

GPL-2.0/3.0

Strong copyleft license requiring source code distribution.

8

#### Flag for Review

LGPL

Weak copyleft license for libraries.

MPL

Weak copyleft with file-level requirements.

EPL

Weak copyleft with patent termination clause.

12

#### Approve

MIT

Permissive license with minimal restrictions.

BSD

Permissive license with minimal conditions.

Apache-2.0

Permissive license with patent grant.

FIX

### Remediate Issues

Quickly fix vulnerabilities and compliance issues with actionable recommendations.

#### Developer-First Remediation

Quickly remediate dependency issues with automated suggestions and fix plans.

[Developer-first feedback integrated into code review and CI/CD](https://fossa.com/docs/)

Automated remediation suggestions & fix recommendations

Guided resolution and escalation workflows for legal / security team assist

[Impact analysis for dependency changes](https://fossa.com/docs/impact-analysis/)

Flagged

### GPL-2.0-only

in

diff-lcs

(1.2.4)

Activein3Projects

DISCOVEREDLicense discovered in source code files.

#### GNU General Public License v2.0 only

You may copy, distribute and modify the software as long as you track changes/dates in source files. Any modifications to or software including (via compiler) GPL-licensed code must also be made available under the GPL along with build & install instructions.

diff-lcs

docs/COPYING.txt

GPL-2.0-only license detected in this file

|  |  |
| --- | --- |
| 1 | GNU GENERAL PUBLIC LICENSE |
| 2 | Version 2, June 1991 |
| 3 |  |
| 4 | Copyright (C) 1989, 1991 Free Software Foundation, Inc., |
| 5 | 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA |
| 6 | Everyone is permitted to copy and distribute verbatim copies |
| 7 | of this license document, but changing it is not allowed. |
| 8 |  |
| 9 | Preamble |
| 10 |  |
| 11 | The licenses for most software are designed to take away your |
| 12 | freedom to share and change it. By contrast, the GNU General Public |

REPORT

### Audit Grade Reporting

From critical documentation to routine housekeeping — all reporting is fully automated in the background, letting you focus on building something great.

#### Always-On, Always-Ready

Generate comprehensive reports with automated attributions and vulnerability documentation.

[Automated attributions - hosted, white-label branded or embedded into your product directly](https://fossa.com/solutions/oss-license-compliance.md)

[Full audit-ready reports - equivalent to M&A code scan services](https://fossa.com/solutions/due-diligence.md)

[Vulnerability remediation reporting, performance and external-ready documentation](https://fossa.com/solutions/code-security.md)

FOSSA Attribution

https://app.fossa.com/attribution/reports/crowdtiltopen

FOSSA

3rd-Party Software Report for crowdtiltopen

crowdtiltopen

Created with FOSSA

## 3rd-Party Software Report for crowdtiltopen

The following 3rd-party software packages may be used by or distributed withcrowdtiltopen. Any information relevant to third-party vendors listed below are collected using common, reasonable means.

#### Generated

3/22/2025

#### Revision

new changes to structure

### Table of Contents

### Dependencies

[actionmailer (3.2.13)](#)gem\+actionmailer

Email on Rails. Compose, deliver, and test emails using the familiar controller/view pattern. First-class support for multipart email and attachments.

#### Declared License(s)

MIT

Copyright (c) 2004-2011 David Heinemeier Hansson
Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

[react (18.2.0)](#)npm\+react

React is a JavaScript library for building user interfaces.

#### Declared License(s)

MIT

MIT License Copyright (c) Facebook, Inc. and its affiliates.

[lodash (4.17.21)](#)npm\+lodash

Lodash modular utilities.

#### Declared License(s)

MIT

The MIT License Copyright JS Foundation and other contributors.

MANAGE

### Manage Your Supply Chain

Holistic management of your entire software supply chain in one place.

#### Global Package Search

Search across your entire organization's package inventory with advanced filtering and insights.

Unified search across all repositories, packages, and dependencies

Advanced filtering by license, vulnerability, and compliance status

Dependency tree visualization and impact analysis

Real-time package intelligence and security notifications

Integration with package repositories and artifact registries

Packages

15,058

18xx-ti-utils

user+102789

3d-view

npm+3d-view

45454444JavaServer Pages(TM) Standard Tag Library API

mvn+javax.servlet.jsp.jstl:jstl-api

4d63.com/gochecknoglobals

go+4d63.com/gochecknoglobals

7zip

npm+7zip

Quick Filters

NPM

Maven

Go

PyPI

Cargo

Status

All

Blocked

Allowed

#### Public Portals

Generate and maintain public, hosted and brandable portals for SBOMs, attributions and security documentation.

Customizable public attribution portal with your company branding

Automated license notice generation and compliance verification

Version-specific attribution for all product releases

Self-updating notice documents with license text and metadata

Analytics for attribution portal usage and compliance status

FOSSA SBOM Portal

https://sbom.fossa.com/orgs/cncf

Powered byFOSSA

[Learn more about SBOMs](#)•[Create your own SBOM portal](#)

CN

## Cloud Native Computing Foundation (CNCF)

Sustaining and integrating open source technologies to orchestrate containers as part of a microservices architecture.

Public SBOMs

#### containerd

Version 1.7

#### argo-cd

Version 2.10

#### etcd

Version 3.5

#### fluentd

Version 1.16

#### istio

Version 1.21

#### kubernetes

Version 1.29

#### prometheus

Version 2.51

#### open-policy-agent

Version 0.57

#### helm

Version 3.14

#### vitess

Version 19.0

#### Enterprise Dashboard

Get a bird's-eye view of your organization's open source and compliance posture.

Executive-level insights with compliance and security metrics

Team and project performance tracking with custom reports

Automated policy violation detection and remediation tracking

License obligation management and approval workflows

Trend analysis and forecasting for security and compliance risks

### Issues

1/1/25 \- 3/22/25

#### Total

\+42

/ 7,010

#### Active

\+40

/ 1,562

#### Ignored

—

/ 283

#### Remediated

\+27

/ 5,165

Remediated

Ignored

Active

8K

6K

4K

2K

0

Feb 20

Feb 25

Mar 02

Mar 07

Mar 12

Mar 17

Mar 22

#### Role-Based Access Control

Implement granular access controls and secure workflows for your organization.

Custom role definitions with fine-grained permissions

Team and project-based access controls

Secure approval workflows with audit trail

Integration with SSO and identity providers

Compliance with security frameworks and regulations

### Access Control

Manage roles and authentication

Roles

3

Role

Description

Actions

Admin

Full access

EditorDefault

Read and write access to all projects

Viewer

Read-only access

SAML SSO

Disabled

#### Enterprise Integrations

Connect FOSSA with your development ecosystem and enterprise systems.

Seamless integration with CI/CD pipelines and DevOps workflows

API access for custom automation and reporting

Webhook support for real-time notifications and triggers

Enterprise system integrations with JIRA, GitHub, GitLab, etc.

Custom data export for business intelligence tools

Quick Import

Automatically analyze from code host for easy initial results.

Open source management powered by FOSSA, Inc. © 2025

#### Policy Management

Define and enforce license, security, and compliance policies across your organization.

Define organization-wide license and security policies

Create custom policy rules for specific projects or teams

Automated policy enforcement with build-blocking capabilities

Policy exception workflows with approval process

Compliance reporting and audit-ready documentation

Policies/Standard Bundle Distribution

Starter policy template for most types of apps and software bundles.

5

#### Deny

AGPL

Strong copyleft license with strict source code distribution requirements.

GPL-2.0/3.0

Strong copyleft license requiring source code distribution.

8

#### Flag for Review

LGPL

Weak copyleft license for libraries.

MPL

Weak copyleft with file-level requirements.

EPL

Weak copyleft with patent termination clause.

12

#### Approve

MIT

Permissive license with minimal restrictions.

BSD

Permissive license with minimal conditions.

Apache-2.0

Permissive license with patent grant.

### Scan Your Entire SDLC Today

Join thousands of organizations that trust FOSSA to secure their software supply chain and ensure compliance across their development lifecycle.

## Source

Canonical page: https://fossa.com/products/scan/
