LicScan is a free command-line tool for checking project dependencies for license risk and generating software bills of materials (SBOMs) and EU CRA evidence. It supports Go, Node.js, PHP, Python, Ruby, Rust, and Java projects. Its configurable five-level policy model lets users deny, warn about, or allow licenses, with exceptions. Output options include table, JSON, HTML, Markdown, CycloneDX, SPDX, CRA PDF, SARIF, and JUnit. CRA mode creates a PDF and a CRA-extended CycloneDX JSON SBOM with manufacturer and product metadata. The maker says scans run locally without an account, telemetry, backend connection, or phone-home behavior, and that identical inputs produce identical outputs. Its official GitHub Action can comment verdicts on pull requests, fail builds for denied licenses, and upload SBOM artifacts. SARIF supports GitHub Code Scanning; JUnit XML is listed for Jenkins, GitLab CI, and Azure DevOps. LicScan runs on Linux, macOS, and Windows, with Homebrew, curl, and go install options. The free/open-source plan is $0 per scan under Apache 2.0.
Who it is for
LicScan suits developers and teams that need to check dependency licenses and generate SBOMs or EU CRA evidence in local or CI workflows. It supports seven project ecosystems and runs on Linux, macOS, and Windows.
What is good
- Supports seven project ecosystems.
- Five-level policy model includes deny, warn, and allow rules.
- Offers outputs including CycloneDX, SPDX, CRA PDF, SARIF, and JUnit.
- Runs locally without an account or telemetry.
- Free at $0 per scan under Apache 2.0.
What to know first
- Roadmap support for CocoaPods and pub is not yet listed as available.
- The listed interface is a command-line tool.
- No free trial is offered.
Verdict
LicScan combines license policy checks with SBOM and CRA evidence generation, and its local operation avoids an account or backend connection. Its supported ecosystems are Go, Node.js, PHP, Python, Ruby, Rust, and Java; CocoaPods and pub are only on the roadmap.
licscan plans and pricing
All plansCompared on open source license compliance software
- Free plan
- Yes
- Policy enforcement
- both
- Attribution reports
- Yes
- Deployment options
- on-premise
- Source scan methods
- repository

