FOSSology is a free, open-source system for examining software for license, copyright, and export-control information. Upload individual files or packages, then choose scanning agents to unpack and inspect them. Its Nomos scanner uses phrases, regular expressions, and heuristics to identify licenses; Monk compares text with stored license texts or phrases users define. A web interface helps teams review findings, manage license texts, recognize results in bulk, and reuse reviews for files with matching hashes. FOSSology can also identify copyright statements and flag keyword findings for review that may relate to export-control codes. It generates SPDX 2.0 exports, Debian copyright files, hierarchical file lists with license identifiers, and Readme files with identified license and copyright details. The REST API supports CI/CD integration and scan triggering from other applications. Deployment options include Docker, Vagrant with VirtualBox, or source installation. FOSSology is available for Linux, macOS, Windows, web, API, and self-hosted use. Its source code is licensed under GPL-2.0 or LGPL-2.1.
Who it is for
FOSSology suits companies, individuals, and groups that need to examine software for open-source license compliance. Its API and reporting options may also suit teams integrating scans into CI/CD workflows.
What is good
- Free open-source license-compliance toolkit
- Scans files and packages with selected agents
- Supports SPDX 2.0 exports and Debian copyright files
- REST API supports CI/CD integration
- Offers Docker, Vagrant, and source installation
What to know first
- Cannot determine which libraries created a binary
- Community support is voluntary
Freedom251 review
FOSSology: the full review
FOSSology combines scanning, review, and reporting tools for software license and copyright information. It cannot identify libraries used to create a binary, so that task requires binary analysis tools.
Overview
FOSSology is an open-source license-compliance system for teams and individuals who need to scan software files, review findings, and produce compliance reports. Its combination of a web review workflow and automation options makes it a strong fit for source-oriented compliance work, but it does not identify libraries inside binaries.
Key features
- Package and file scanning: Upload individual files or packages, unpack them, and scan their contents with selected agents. Multiple scan methods provide flexibility, though reviewers still need to assess the findings.
- Two license scanners: Nomos uses phrases, regular expressions, and heuristics to identify licenses; Monk compares text with stored license texts or user-defined phrases. The complementary approaches support broad review, rather than making the results a substitute for review.
- Review workflow: The web interface supports license finding review, license-text management, bulk recognition, and aggregated file views. Reusing reviews for files with matching hashes can reduce repeated work across matching content.
- Copyright and export-control checks: FOSSology can find copyright statements and surface keyword-based findings that may relate to export-control codes. Those export-control results are presented for review, not described as a definitive determination.
- Reports and automation: It can produce SPDX 2.0 exports, Debian copyright files, hierarchical file lists with license identifiers, and Readme files containing identified license texts and copyright information. The REST API can support CI/CD integration, uploads and scan triggering from other applications; the command line can retrieve SPDX files.
- Deployment: The project describes Docker, Vagrant with VirtualBox, and source installation. On-premise deployment suits organizations that want to run the system in their own environment.
The key boundary is binary provenance: FOSSology cannot determine which libraries were used to create a binary. A workflow that needs that information requires binary analysis tools as well.
Pricing
FOSSology is free: its plan costs 0.00 USD per free and is described as an open-source license-compliance toolkit and system. The project states that its source code is licensed under GPL-2.0 or LGPL-2.1. No paid tier is needed for the stated toolkit, and no seat or scan quota is attached to the plan.
The free offering includes obligation tracking, attribution reports, SPDX and RDF SBOM import formats, multiple source scan methods, and on-premise deployment. That makes it a practical option for organizations able to install and operate the system themselves. Support is voluntary through the mailing list, with bugs reported through GitHub issues, so organizations needing a specified support commitment should look elsewhere.
Platforms
FOSSology supports API, Linux, macOS, self-hosted, web, and Windows. Its installation options include Docker, Vagrant with VirtualBox, and source installation, giving teams several routes to a self-hosted deployment.
Who it's for
FOSSology suits companies, individuals, and groups seeking to improve their ability to comply with open-source licenses, especially those that want source scanning, reviewable findings, attribution outputs, and integration with CI/CD. It is less suited to users whose primary need is identifying libraries embedded in binaries or who require a formal support service.
Pros and cons
Pros
- Free and open source: The 0.00 USD per free plan combines scanning, obligation tracking, attribution reports, and on-premise deployment.
- Review is part of the workflow: Bulk recognition, aggregated views, and hash-matched review reuse can help manage findings across files.
- Useful automation and outputs: REST API integration and several report formats make it applicable to compliance processes beyond manual scans.
Cons
- No binary library identification: Teams need separate binary analysis tools for that task.
- Community support is voluntary: The mailing list and GitHub issues do not amount to a stated support commitment.
- Self-hosting calls for operational ownership: Installation options are provided, but the deployment model is on-premise rather than a managed hosted service.
Alternatives
For a broader open-source license compliance software shortlist, compare the available approaches before choosing a workflow.
- Apache Flink CDC is another free option, with released JARs and connectors under Apache License 2.0; consider it if those are the materials you need rather than FOSSology's compliance system.
- licscan is a free, standalone CLI under Apache 2.0, priced at $0 per scan. Choose it if a command-line tool is a better fit than FOSSology's web review workflow.
- OHRisk is a free open-source CLI under the MIT License. It is an alternative to consider if you prefer a CLI approach.
- REUSE Tool is free, requires no registration, and can be used offline. It may fit users who prioritize offline use over FOSSology's web interface and API workflow.
- ScanCode Toolkit is a free software code-scanning tool. Consider it as another free scanning option if you do not need FOSSology's particular review and reporting workflow.
- Double Open Compliance has a free SaaS tier. Consider it if you want a web-based SaaS option rather than FOSSology's on-premise deployment.
- FOSSA offers a free forever tier capped at 5 projects, 10 contributing developers, 1 release group, and 5 dependency levels for scans, plus a free trial. It may suit a small project set that fits those limits and wants a freemium service.
- SourceTrust offers a free option for eligible public GitHub repositories, subject to fair use and SourceTrust attribution. Consider it if your work fits that repository-based scope.
Verdict
Choose FOSSology if you need a free, self-hosted system for source-oriented license and copyright scanning, review, and reporting, with API support for automation. Its clearest advantage is putting scan findings and compliance outputs into one workflow without a software charge. Look elsewhere if binary library identification is essential or if your team needs committed vendor support.
FOSSology plans and pricing
All plansCompared on open source license compliance software
- Free plan
- Yes
- Obligation tracking
- Yes
- Attribution reports
- Yes
- SBOM import formats
- SPDX; RDF
- Deployment options
- on-premise
- Source scan methods
- multiple

