Skip to content
@fossid-ab

FossID

Software Composition Analysis

👋 We're FossID

Software Composition Analysis

FossID helps you find all open source software in your codebase no matter how it was introduced, identify license compliance and security vulnerability risks, and generate complete software bills of material (SBOMs) to meet industry regulations and customer demands.

Maximize Developer Productivity. Minimize Business Risk.

FossID SCA tools provide the most comprehensive scanning capabilities, flexible workflow customizations, granular governance and administration, multiple reporting formats, and deployment options that offer maximum privacy and confidentiality.

Highlights

  • 🔍 Complete Codebase Scanning: Scan your entire codebase (not just declared dependencies) so you can detect all open source regardless of how it was introduced.
  • 🧩 Code Snippet Detection: Find the smallest blocks of open source so your team can confidently leverage AI-generated code with visibility into license or security risk.
  • ⚠️ Vulnerable Snippet Finder: Identify precise blocks of known vulnerable code so your team can remediate efficiently and leave no doubt about your security posture.
  • 📑 SBOM Management: Ingest supplier SBOMs, consolidate and export NTIA-compliant SBOMs so you can easily meet regulatory security requirements.
  • 🧑‍💻 SDLC Integration: Include SCA at the developer workstation, Git-based SCM, CI/CD pipelines, or issue tracking and notification systems.
  • 💪 Custom Workflows: Use the Workbench web app UI, the CLI, or our API for maximum productivity.

More Information

For more information about FossID, contact us at www.fossid.com or email us at [email protected].

Popular repositories Loading

  1. workbench-agent workbench-agent Public

    The Workbench-Agent is a Python script used for integrating with FossID Workbench in CI/CD pipelines. It leverages the Workbench API in order to upload code, scan code and retrieve various types of…

    Python 2 3

  2. .github .github Public

Repositories

Showing 2 of 2 repositories
  • workbench-agent Public

    The Workbench-Agent is a Python script used for integrating with FossID Workbench in CI/CD pipelines. It leverages the Workbench API in order to upload code, scan code and retrieve various types of results.

    fossid-ab/workbench-agent’s past year of commit activity
    Python 2 MIT 3 0 0 Updated Jul 10, 2024
  • .github Public
    fossid-ab/.github’s past year of commit activity
    0 0 0 0 Updated Feb 17, 2024

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Top languages

Python

Most used topics

Loading…