Ross ROSS = Recommend OSS · open-source software intelligence for agents

aboutcode-org/scancode-toolkit

:mag: ScanCode detects licenses, copyrights, dependencies by "scanning code" ... to discover and inventory open source and third-party packages used in your code. Sponsored by NLnet, the Google Summer of Code, Azure credits, nexB and other generous sponsors! observed · 2026-08-28

github.com/aboutcode-org/scancode-toolkit · homepage · Python · NOASSERTION (other) observed · 2026-08-28

Health v2 · maintenance only

94/100

  • Activity 99
  • Release rhythm 84
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 57
  • age_days: 4081
  • days_rel: 26
  • days_push: 8
  • n_releases_24m: 10

Full methodology

Adoption not part of the score

2612 stars · 770 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

ScanCode Toolkit is a command-line tool and Python library that scans codebases to detect licenses, copyrights, package manifests, dependencies, and vulnerabilities in source and binary files. It produces inventories of open source and third-party packages and can generate SBOMs in SPDX and CycloneDX formats.

Use cases

  • detect open source licenses in a codebase
  • generate an SBOM for my project
  • find copyrights and license notices in source files
  • inventory third-party dependencies and packages
  • check license compliance before releasing software
  • generate attribution documents for used open source packages
  • scan binaries and source for license and vulnerability info

When to choose

  • you need accurate, best-in-class license and copyright detection across large codebases
  • you want a standalone CLI that embeds easily in CI/CD pipelines
  • you need SPDX or CycloneDX SBOM generation
  • you run Windows, macOS, or Linux and want a heavily tested tool

When to avoid

  • you need a web UI and scan project management - use the companion ScanCode.io app instead
  • you only need dependency resolution for a single package manager rather than full license scanning
  • you want real-time container or runtime security scanning rather than static code analysis

Facets

cli-tool · maturity active

security parser developer-tools cli developer-tools security legal windows python cli license-scanning sbom spdx cyclonedx software-composition-analysis copyright-detection open-source-compliance package-url automation linux macos

2 sources

Member repositories

RepositoryRoleHealth v2
aboutcode-org/scancode-toolkitmain94

For agents

markdown · JSON · MCP: product_card(name="aboutcode-org/scancode-toolkit")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem