FOSSology

B
B tier on Open Source License Compliance SoftwareScore 7.2 · #1 of 28
Android app
Not listed
Free plan
Yes
Runs on
api, Linux, Mac, self-hosted, Web, Windows

Summary

FOSSology is a free, open-source system for finding license, copyright, and export-control information in software. Users submit files or packages for unpacking and scanning with selected agents. Nomos detects license indicators using phrases, regular expressions, and heuristics, while Monk compares text with saved license texts or phrases supplied by users. Its web interface supports review of findings, license-text management, bulk recognition, aggregated file views, and reuse of reviews for files with matching hashes. FOSSology can also identify copyright statements and surface keyword matches for review when they may concern export-control codes. It produces SPDX 2.0 exports, Debian copyright files, hierarchical file lists with license identifiers, and Readme files containing identified license texts and copyright information. A REST API supports CI/CD integration, package uploads, and scan triggering from other applications; the command line can retrieve SPDX files. Deployment options include Docker, Vagrant with VirtualBox, or installing from source. The source code is licensed under GPL-2.0 or LGPL-2.1. One stated limitation is that it cannot determine which libraries were used to create a binary.

Who it is for

FOSSology is aimed at companies, individuals, and groups seeking to improve their open-source license compliance processes. It may also suit teams that need scan results and reports integrated into CI/CD workflows.

What is good

  • Scans files and packages with selectable agents.
  • Includes two license-scanning approaches.
  • Generates SPDX 2.0 exports and Debian copyright files.
  • REST API supports CI/CD integration.
  • Available for free under GPL-2.0 or LGPL-2.1.

What to know first

  • Cannot identify libraries used to create a binary.
  • Community support is voluntary.
  • Deployment requires Docker, Vagrant, or source installation.

Everything Xiaomi review

FOSSology: the full review

FOSSology combines software scanning, review tools, reports, and API access in a free toolkit. Its stated inability to identify libraries in binaries is important for teams that need that analysis.

FOSSology is an open-source toolkit for examining software for licensing, copyright, and export-control information. It is best suited to teams and individuals who need a reviewable compliance workflow they can run on-premise or connect to CI/CD. Its source-level scanning and reporting are useful; it is not a substitute for binary analysis when you need to identify bundled libraries.

Overview

FOSSology takes individual files or software packages, unpacks packages when needed, and scans them with selected agents. Its web interface gives reviewers a place to assess findings and reuse decisions for files with matching hashes, while reports and API access help carry results into compliance processes.

The distinction between identifying license evidence and identifying software components matters. FOSSology can surface license and copyright information in scanned files, but cannot determine which libraries were used to create a binary. Teams that need that analysis should use binary analysis tools alongside it.

Key features

  • Two license scanners: Nomos looks for license indicators using phrases, regular expressions, and heuristics. Monk compares text with stored license texts or user-defined phrases. Using both gives reviewers complementary ways to surface candidate license evidence, but findings still need review.
  • Review workflow: The web interface supports reviewing findings, managing license texts, bulk recognition, and aggregated file views. Reusing reviews for matching file hashes can reduce repeated work when the same files recur.
  • Copyright and export-control checks: The system finds copyright statements and surfaces keyword-based findings that may relate to export-control codes. Those keyword findings are material for review, not a determination that a code applies.
  • Compliance outputs: FOSSology can generate SPDX 2.0 exports, Debian copyright files, hierarchical file lists with license identifiers, and Readme files containing identified license texts and copyright information. These formats support different reporting needs without making the scan itself a final legal assessment.
  • Automation: Its REST API supports CI/CD integration, uploads and scan triggering from other applications, and command-line retrieval of SPDX files. That makes it more suitable for repeatable pipelines than a purely manual review tool.
  • Deployment and licensing: Installation options include Docker, Vagrant with VirtualBox, or source installation. The project licenses its source code under GPL-2.0 or LGPL-2.1.

Pricing

FOSSology is free: its plan costs 0.00 USD per free and covers the open-source license-compliance toolkit and system. There is no paid tier or seat or scan quota to weigh in the plan described here. Its on-premise deployment is a fit for organizations that want to operate the system themselves; the trade-off is that deployment and support rely on the project’s installation options and voluntary community support through its mailing list. Bug reports can be filed through GitHub issues.

Platforms

FOSSology supports API, Linux, macOS, self-hosted, web, and Windows. Its documented deployment choices are Docker, Vagrant with VirtualBox, or source installation, making it a flexible fit for teams prepared to manage their own setup.

Who it's for

FOSSology suits companies, individuals, and groups seeking to improve open-source license compliance through scan review, obligation tracking, attribution reports, and SPDX or RDF SBOM import. It is a particularly good fit when teams need to examine files or packages, retain review work, and automate uploads or report retrieval. It is a weaker fit when the main requirement is identifying libraries inside binaries or when a team needs dedicated commercial support.

Pros and cons

  • Pro: Multiple scanners, a web review workflow, and reusable reviews help turn raw findings into repeatable compliance work.
  • Pro: SPDX, Debian copyright, hierarchical file-list, and Readme outputs cover several practical reporting formats.
  • Pro: API and command-line options make CI/CD integration and automated SPDX retrieval possible.
  • Con: It cannot identify libraries used to create a binary, so binary analysis needs another tool.
  • Con: Community support is voluntary, which may not meet teams that require a contracted support channel.
  • Con: Self-hosting and several installation routes give teams control, but also leave setup and operation to them.

Alternatives

Compare open-source license compliance software if you want to weigh FOSSology against other tools in the category.

  • OHRisk is a free open-source CLI for Linux, macOS, and Windows; choose it if a command-line tool is the better fit.
  • ScanCode Toolkit is a free software code scanning tool with API, self-hosted, and desktop platform support; consider it as another free scanning option.
  • Apache Flink CDC is free, with released JARs and connectors under Apache License 2.0; its stated focus is distinct from FOSSology’s compliance workflow.
  • licscan is a free standalone CLI at $0 per scan under Apache 2.0; pick it if that form and licensing model suit your needs.
  • SourceTrust has a free open-source plan for eligible public GitHub repositories, subject to fair use and SourceTrust attribution, plus a 29.00 USD per month per-project plan. Consider it if a web-based project service is preferable.
  • Double Open Compliance offers a free SaaS tier and supports API, self-hosted, and web use; consider it if SaaS is part of your preference.
  • FOSSA has a free plan capped at 5 projects, 10 contributing developers, 1 release group, 5 dependency levels for scans, and 1 quality check. Its freemium model and free trial may suit teams that prefer that route and can work within the caps.
  • REUSE Tool is free, needs no registration, and can be used offline; choose it if those characteristics are more important to your workflow.

Verdict

Choose FOSSology if you need a free, on-premise license-compliance system with review tools, useful report formats, and API support for automation. Its clearest reason to look elsewhere is binary component identification; teams needing that should pair FOSSology with binary analysis or choose a tool that covers that requirement.

FOSSology plans and pricing

All plans
FOSSology Free Open-source license compliance toolkit and system fossology.org · 30 Sept 2026

Compared on open source license compliance software

Free plan
Yesfossology.org
Obligation tracking
Yesfossology.org
Attribution reports
Yesfossology.org
SBOM import formats
SPDX; RDFfossology.org
Deployment options
on-premisefossology.org
Source scan methods
multiplefossology.org

Facts

Purpose
FOSSology is an open-source license-compliance system and toolkit for scanning software for license, copyright, and export-control information.fossology.org · 30 Sept 2026
Scanning workflow
Users can upload individual files or software packages, which FOSSology can unpack and scan using selected agents.fossology.org · 30 Sept 2026
License scanners
Nomos identifies licenses using phrases, regular expressions, and heuristics, while Monk compares text against stored license texts or user-defined phrases.fossology.org · 30 Sept 2026
Review tools
The web interface supports reviewing license findings, managing license texts, bulk recognition, aggregated file views, and reuse of reviews for files with matching hashes.fossology.org · 30 Sept 2026
Copyright and export-control scans
FOSSology can find copyright statements and let users review keyword-based findings that may relate to export-control codes.fossology.org · 30 Sept 2026
Reports
FOSSology can generate SPDX 2.0 exports, Debian copyright files, hierarchical file lists with license identifiers, and Readme files containing identified license texts and copyright information.fossology.org · 30 Sept 2026
Automation and API
The REST API supports CI/CD integration, package uploads and scan triggering from other applications, and command-line retrieval of SPDX files.fossology.org · 30 Sept 2026
Deployment
The project describes installation using Docker, Vagrant with VirtualBox, or source installation.fossology.org · 30 Sept 2026
License
The project states its source code is licensed under GPL-2.0 or LGPL-2.1.fossology.org · 30 Sept 2026
Support
The project provides voluntary community support through its mailing list and invites users to report bugs through GitHub issues.fossology.org · 30 Sept 2026
Known limitation
FOSSology cannot determine which libraries were used to create a binary and says binary analysis tools are needed for that task.fossology.org · 30 Sept 2026
Intended users
The project says its community includes companies, individuals, and groups using the toolkit or system to improve their ability to comply with open-source licenses.fossology.org · 30 Sept 2026

Best FOSSology alternatives

See all 12

Where it ranks on Everything Xiaomi

Is FOSSology yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources