licscan
- Android app
- Not listed
- Free plan
- Yes
- Runs on
- Linux, Mac, Windows

Summary
LicScan is a command-line tool for checking project dependencies for license risk and producing software bills of materials (SBOMs) and EU CRA evidence. It supports Go, Node.js, PHP, Python, Ruby, Rust, and Java projects. Its configurable five-level policy model lets teams deny, warn about, or allow licenses, with exceptions. Outputs include table, JSON, HTML, Markdown, CycloneDX, SPDX, CRA PDF, SARIF, and JUnit formats. CRA mode creates a PDF and an extended CycloneDX JSON SBOM with manufacturer and product metadata. The maker says scans run locally without an account, telemetry, or backend connection, and that identical inputs produce identical outputs. Its GitHub Action can post scan verdicts on pull requests, fail builds for denied licenses, and upload SBOM artifacts; SARIF and JUnit outputs support other CI workflows. It runs on Linux, macOS, and Windows, and can be installed with Homebrew, curl, or go install. LicScan is free under Apache 2.0.
Who it is for
LicScan suits development teams that need license-policy checks and SBOM or CRA outputs in repository and CI workflows. It supports several programming ecosystems and runs on Linux, macOS, and Windows.
What is good
- Supports seven project ecosystems.
- Configurable five-level license risk policy.
- Outputs include CycloneDX, SPDX, SARIF, and JUnit.
- Runs locally without an account or telemetry.
- Free under Apache 2.0.
What to know first
- No free trial is listed.
- CocoaPods and pub support is only on the roadmap.
Verdict
LicScan brings dependency license checks, policy enforcement, and multiple SBOM and compliance outputs to a free command-line tool. Its supported ecosystems and CI integrations make it relevant for teams that want these checks in repository workflows.
licscan plans and pricing
All plansCompared on open source license compliance software
- Free plan
- Yeslicscan.dev
- Policy enforcement
- bothlicscan.dev
- Attribution reports
- Yeslicscan.dev
- Deployment options
- on-premiselicscan.dev
- Source scan methods
- repositorylicscan.dev
Facts
- Purpose
- LicScan scans project dependencies for license risk and generates SBOMs and EU CRA evidence.licscan.dev · 3 Oct 2026
- Supported ecosystems
- It supports Go, Node.js, PHP, Python, Ruby, Rust, and Java projects.licscan.dev · 3 Oct 2026
- License policy
- A configurable five-level risk model supports deny, warn, and allow exceptions.licscan.dev · 3 Oct 2026
- Reports
- Output formats include table, JSON, HTML, Markdown, CycloneDX, SPDX, CRA PDF, SARIF, and JUnit.licscan.dev · 3 Oct 2026
- CRA evidence
- CRA mode generates a PDF report and a CRA-extended CycloneDX JSON SBOM with manufacturer and product metadata.licscan.dev · 3 Oct 2026
- Security and privacy
- The site says LicScan runs locally without an account, telemetry, backend connection, or phone-home behavior.licscan.dev · 3 Oct 2026
- Reproducibility
- The maker describes scans as deterministic, with the same inputs producing the same outputs.licscan.dev · 3 Oct 2026
- GitHub Actions
- The official GitHub Action can comment scan verdicts on pull requests, fail builds on denied licenses, and upload SBOM artifacts.licscan.dev · 3 Oct 2026
- Other CI integrations
- The maker describes SARIF support for GitHub Code Scanning and JUnit XML support for Jenkins, GitLab CI, and Azure DevOps.licscan.dev · 3 Oct 2026
- Supported package managers
- The homepage lists seven ecosystems, with roadmap support for CocoaPods and pub.licscan.dev · 3 Oct 2026
- Installation
- Install options shown include Homebrew, curl, and go install.licscan.dev · 3 Oct 2026
- Support
- The maker directs bug reports to GitHub issues and provides [email protected] for contact.licscan.dev · 3 Oct 2026
- Maker
- The website identifies codelake Technologies LLC as the maker.licscan.dev · 3 Oct 2026
Company
- Headquarters
- Wyoming, USAlicscan.dev · 28 Sept 2026
Best licscan alternatives
See all 20Where it ranks on Everything Xiaomi
Is licscan yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- licscan.dev· checked 3 Oct 2026

