Run scans and track all the open source and third-party products and components used in your software.
Apply usage policies at the license or component level, and integrate into ScanCode to ensure compliance.
Capture software inventories (SBOMs), generate compliance artifacts, and keep historical data.
Ensure FOSS compliance with enterprise-grade features and integrations for DevOps and software systems.
DejaCode is your system of record as a single source of truth with quality data for licenses, vulnerabilities, and package provenance and metadata:
Scan a software package with ScanCode, simply by providing its Download URL, to get comprehensive details of its composition and create an SBOM.
Track all the open source and third-party components used in your software across products and teams, including:
Share data from scans, policy reviews and approvals, and reports across the organization for a consistent view of packages, licenses, and security risks across teams.
Implement clear usage policies for low-cost, low-friction compliance across teams to ensure consistent use of open source components.
Customize policies at the license or component/package level, based on your organization’s needs and legal requirements:
Integrate policies with ScanCode to uncover licensing issues:
Quickly identify known vulnerabilities by package, with VulnerableCode:
Create, publish and share SBOM documents in DejaCode, for both CycloneDX and SPDX standard formats.
Generate compliance artifacts, including including detailed attribution documentation and custom reports in multiple file formats, and keep historical data for an audit trail of compliance activities.
Manage organizational complexity with enterprise-grade features and integrations for DevOps and software systems.
Aggregate SBOM data across products and teams.
DejaCode delivers efficient and automated open source license and security compliance with enterprise-level SCA:
Consolidate SCA and SBOM data – both public and curated, informed by your policies – with a consistent view of packages, licenses, and security risks across the entire organization.
Enforce consistent use of open source software, with continuous vulnerability reporting, across teams and products.
Export, import, merge, combine, and organize SBOMs, continuously and effectively.
The AboutCode stack is 100% open source and uses 100% open data. We are committed to the principles of open development. But we need your help.
We could really use your help to pay the folks building these open source projects. Sponsoring AboutCode projects on GitHub goes directly to the maintainers and developers working on open source AboutCode projects.
Need more hands-on support? Get help from the experts! nexB offers advanced support plans and other professional services.
© AboutCode Europe ASBL. All rights reserved.