Fast, portable and reliable dependency analysis for any codebase. Supports license & vulnerability scanning for large monoliths. Language-agnostic; integrates with 20+ build systems.
Fossa CLI is a dependency analysis tool designed for codebases of any size or complexity, providing fast, portable, and reliable scanning for license compliance and security vulnerabilities across large monolithic projects. The tool is language-agnostic and integrates with over twenty different build systems, making it adaptable to diverse development environments. Built in both Haskell and Rust, the project emphasizes code quality through strict compiler and linter standards, comprehensive testing, and detailed style guides for each language. The CLI operates through analysis strategies that discover and examine project dependencies, with features including container image scanning, SBOM file analysis, manual dependency specification, and custom license and keyword searching capabilities.