Skip to main content
FOSSA Logo
C/C++ Software Composition Analysis

Understand the open source in your C/C++ codebase

Identify vendored libraries and copied code, review license and vulnerability findings, and include vendor dependencies in your SBOMs and licensing reports.

Illustrative example of a vendor inventory.

Your dependency inventory needs more than one scanning method

Bring vendor dependency detection, snippet scanning, and manual dependency additions into your C/C++ review workflow. They work together, not as separate products.

Vendored libraries

Identify top-level libraries in directories such as /vendor and /third-party, and list them as first-class entries in your dependency inventory.

Copied code

Run snippet scanning alongside vendor detection. When a dependency shows up as a snippet but not as a vendor dependency, you can promote it manually.

Hard-to-identify packages

Manually add obscure or proprietary dependencies. FOSSA attempts to verify and match them, and flags any entry it cannot verify so you can still add it.

Find dependencies and see where they live

Explore detected vendor dependencies in a dedicated inventory view, with file-level context to support review.

  1. 1

    Start a scan

    Run the FOSSA CLI against your C/C++ project.

  2. 2

    Open the vendor inventory

    Review detected vendor dependencies in a dedicated section.

  3. 3

    Select a dependency

    See its version, GitHub locator, and file path.

  4. 4

    Navigate to its location

    Jump through the file tree down to the vendor folder.

Each vendor dependency shows its version, GitHub locator, and file path, so reviewers can go from a finding straight to the code that introduced it.

Review license and security findings alongside your dependencies

Move from discovery to action without leaving the dependency record.

License compliance

  • See the license concluded for each dependency
  • Connect findings to your existing compliance workflows
  • Include vendor dependencies in licensing reports

Security visibility

  • See the security issues associated with each dependency
  • Review CVEs, CWEs, and EPSS scores
  • Keep findings alongside dependency details

Include vendor dependencies in your SBOMs and licensing reports

Carry detected vendor dependencies into the reports your teams use to document their software inventory and licensing findings. Vendor dependencies are included in SBOMs and licensing reports by default.

Match the scanning approach to your environment

Different C/C++ projects need different discovery methods. Find the closest match to yours.

Recommended scanning approach by C/C++ environment
Your environmentWhere to start
Top-level vendored source librariesStart with vendor dependency detection.
Broader source-code discoveryCombine vendor detection with snippet scanning.
Yocto buildsTalk to our team about analyzing dependencies during your BitBake build.
Firmware or binaries without sourceTalk to our team about binary analysis and which formats it supports.

For complex C/C++ and embedded-software environments

Manufacturers with large, long-lived C/C++ codebases need broad dependency coverage. Explore how C/C++ dependency visibility fits into your broader software-compliance program.

Frequently asked questions

What to expect when you scan C/C++ with FOSSA.

Can I scan without source code?

FOSSA offers binary analysis for firmware and compiled code. Which binary formats are supported depends on your environment, so talk to our team before planning a binary-only workflow.

What happens when a dependency isn't detected?

If a dependency appears as a snippet but not as a vendor dependency, you can promote it manually. For anything else, add it by hand. FOSSA attempts to verify and match the entry, and flags it when it cannot be verified.

Does FOSSA detect every dependency automatically?

No single method finds everything, which is why FOSSA combines vendor detection, snippet scanning, and manual additions. Vendor detection works best on top-level libraries. Nested or transitive vendored components are harder targets and may need snippet scanning or a manual addition.

Is C/C++ included in my subscription?

Packaging varies by plan. Talk to our team to confirm what is included for your organization.

See what FOSSA finds in your C/C++ codebase

Run a scan, or book a guided demo and we will walk through the results with you.