Ross ROSS = Recommend OSS · open-source software intelligence for agents

fossas/fossa-cli

Fast, portable and reliable dependency analysis for any codebase. Supports license & vulnerability scanning for large monoliths. Language-agnostic; integrates with 20+ build systems. observed · 2026-08-28

github.com/fossas/fossa-cli · homepage · Haskell · NOASSERTION (other) observed · 2026-08-28

Health v2 · maintenance only

95/100

  • Activity 99
  • Release rhythm 87
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 6.0
  • age_days: 3157
  • days_rel: 8
  • days_push: 7
  • n_releases_24m: 91

Full methodology

Adoption not part of the score

1516 stars · 205 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

FOSSA CLI is a zero-configuration, language-agnostic dependency analysis tool that detects dependencies in any codebase across 20+ build systems. It integrates with the FOSSA platform for license compliance scanning, vulnerability detection, and attribution report generation.

Use cases

  • scan my repo for open source license compliance
  • find CVEs in my project dependencies
  • generate an SBOM for my codebase
  • analyze dependencies in a large monorepo
  • generate license attribution reports for release
  • enforce license policy in CI/CD
  • detect vendored dependencies without manifests

When to choose

  • you need license and vulnerability scanning across many languages and build systems
  • you have a large monolith or monorepo that other scanners struggle with
  • you want CI/CD policy enforcement for open source compliance
  • you need attribution notices or SBOMs for legal/regulatory requirements

When to avoid

  • you want a fully offline, self-contained scanner without the FOSSA cloud service
  • you only need a simple SBOM export from a single ecosystem's package manager
  • you cannot send code metadata to a third-party service

Facets

cli-tool · maturity active

security vulnerability-scanning dependency-audit developer-tools ci-cd security developer-tools legal windows cli cross-platform license-scanning sbom dependency-analysis software-supply-chain polyglot monorepo devops linux macos

9 sources

Member repositories

RepositoryRoleHealth v2
fossas/fossa-climain95

For agents

markdown · JSON · MCP: product_card(name="fossas/fossa-cli")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem