Your dependency inventory needs more than one scanning method
Bring vendor dependency detection, snippet scanning, and manual dependency additions into your C/C++ review workflow. They work together, not as separate products.
Vendored libraries
Identify top-level libraries in directories such as /vendor and /third-party, and list them as first-class entries in your dependency inventory.
Copied code
Run snippet scanning alongside vendor detection. When a dependency shows up as a snippet but not as a vendor dependency, you can promote it manually.
Hard-to-identify packages
Manually add obscure or proprietary dependencies. FOSSA attempts to verify and match them, and flags any entry it cannot verify so you can still add it.
Find dependencies and see where they live
Explore detected vendor dependencies in a dedicated inventory view, with file-level context to support review.
- 1
Start a scan
Run the FOSSA CLI against your C/C++ project.
- 2
Open the vendor inventory
Review detected vendor dependencies in a dedicated section.
- 3
Select a dependency
See its version, GitHub locator, and file path.
- 4
Navigate to its location
Jump through the file tree down to the vendor folder.
Each vendor dependency shows its version, GitHub locator, and file path, so reviewers can go from a finding straight to the code that introduced it.
Review license and security findings alongside your dependencies
Move from discovery to action without leaving the dependency record.
License compliance
- See the license concluded for each dependency
- Connect findings to your existing compliance workflows
- Include vendor dependencies in licensing reports
Security visibility
- See the security issues associated with each dependency
- Review CVEs, CWEs, and EPSS scores
- Keep findings alongside dependency details
Match the scanning approach to your environment
Different C/C++ projects need different discovery methods. Find the closest match to yours.
| Your environment | Where to start |
|---|---|
| Top-level vendored source libraries | Start with vendor dependency detection. |
| Broader source-code discovery | Combine vendor detection with snippet scanning. |
| Yocto builds | Talk to our team about analyzing dependencies during your BitBake build. |
| Firmware or binaries without source | Talk to our team about binary analysis and which formats it supports. |
Frequently asked questions
What to expect when you scan C/C++ with FOSSA.
Can I scan without source code?
FOSSA offers binary analysis for firmware and compiled code. Which binary formats are supported depends on your environment, so talk to our team before planning a binary-only workflow.
What happens when a dependency isn't detected?
If a dependency appears as a snippet but not as a vendor dependency, you can promote it manually. For anything else, add it by hand. FOSSA attempts to verify and match the entry, and flags it when it cannot be verified.
Does FOSSA detect every dependency automatically?
No single method finds everything, which is why FOSSA combines vendor detection, snippet scanning, and manual additions. Vendor detection works best on top-level libraries. Nested or transitive vendored components are harder targets and may need snippet scanning or a manual addition.
Is C/C++ included in my subscription?
Packaging varies by plan. Talk to our team to confirm what is included for your organization.