Skip to main content
S

SCANOSS

This company offers an open-source software composition analysis platform that automates the creation of software bills of materials (SBOMs) with continuous live code analysis. Their platform integrates into existing development workflows, providing developers with real-time insights into license compliance and open-source vulnerabilities. This enables faster, more secure code development and improved supply chain visibility.

Madrid, SpainFounded 2021253K+ followers
Updated 4 months ago

Funding

Funding not disclosed

Funding rounds are not available yet.

Founders

Product

Problem

Organizations face challenges in identifying undeclared open-source software (OSS), legacy components, and AI-generated code within their software supply chain, leading to potential security vulnerabilities and compliance issues. Relying solely on declared OSS can leave teams unaware of hidden, outdated, or plagiarized code, including C/C++ fragments. This lack of visibility increases the risk of license violations, security breaches, and supply chain attacks.

Solution

SCANOSS provides an open-source software composition analysis (SCA) platform that automates the creation of software bills of materials (SBOMs) with continuous live code analysis. The platform detects declared and undeclared open-source software, including AI-generated code and C/C++ fragments. By integrating into existing development workflows, SCANOSS offers real-time insights into license compliance, security vulnerability risks, and geo provenance. The SCANOSS Open Source Software Knowledge Base (OSS KB) is universally accessible through open APIs, enabling comprehensive software supply chain transparency and risk management.

Target Audience

The primary users are businesses and development teams seeking to identify open source components, build complete SBOMs, and manage OSS risks within their software supply chain.

Features

  • Automated SBOM generation with continuous live code analysis
  • Detection of declared and undeclared open-source software, including AI-generated code
  • Identification of licenses, security vulnerabilities, and geo provenance
  • Open APIs for accessing the Open Source Software Knowledge Base (OSS KB)
  • Integration with development pipelines and delivery processes
  • Pre-commit hooks integration
  • Container scanning capabilities
  • SBOM Workbench for code comparison
This profile is AI-generated and may contain inaccuracies.