Generated by All in One SEO v4.9.1.1, this is an llms.txt file, used by LLMs to index the site. # nexB What's in your software! ## Sitemaps - [XML Sitemap](https://nexb.com/sitemap.xml): Contains all public & indexable URLs for this website. ## Posts - [Blog](https://nexb.com/blog/) - Read posts on open source, compliance, SCA, and more from the nexB team. - [OSS Attribution Case Study: DataTables and Healthcare.gov](https://nexb.com/datatables-and-healthcare-gov-oss-attribution-case-study/) - Developers are not likely to do a good job fulfilling OSS obligations without clear guidance. OSS Attribution Case Study with DataTables and Healthcare.gov - [Best Practices for Open Source Software (OSS) Attribution](https://nexb.com/oss-attribution-best-practices/) - What is actually legally required? What is the best way to meet FOSS attribution obligations? OSS attribution obligations and best practices for OSS attribution - [What is Open Source Software (OSS)? And Is It Free to Use?](https://nexb.com/what-is-open-source-software/) - Open source software (OSS) is software composed of source code open to the general public. Open source software is software composed of source code open to all. - [What are the Benefits of Using Open Source Software?](https://nexb.com/what-are-the-benefits-of-open-source-software/) - Free/Libre Open Source Software (FLOSS) refers to freedom (libre), not price. There are benefits of using Free/Libre Open Source Software (FLOSS). - [Software Dependencies: A not-too-technical guide](https://nexb.com/software-dependencies-a-not-too-technical-introduction/) - Larger software systems and products are assembled from many software components. Software systems and products can have many software dependencies - [Wix vs. WordPress and what we can learn about the GPL](https://nexb.com/wix-vs-wordpress-and-what-we-can-learn-about-the-gpl/) - "If I were being honest, I'd say that Wix copied WordPress without attribution..." Wix vs. Wordpress and learn about the GPL License - [Is a page that contains Javascript considered redistribution?](https://nexb.com/open-source-answers-is-publishing-a-page-that-contains-javascript-redistribution/) - JavaScript in a web page is code redistributed to whoever loads this page in their browser. An open discussion on Javascript redistribution - [Open Source Stack Exchange: Can a team be a copyright holder?](https://nexb.com/open-source-answers-can-a-team-be-a-copyright-holder/) - Concise copyright statements are better for both your team and your users. What are the team eligibility to become a copyright holder? - [What are the membership levels in the Linux Foundation?](https://nexb.com/open-source-answers-what-are-the-differences-between-membership-levels-in-the-linux-foundation/) - Open Source Stack Exchange answers questions about the business of open source. The Linux Foundation is dedicated to fostering the growth of Linux. - [Meet purl: a "mostly" universal software package URL](https://nexb.com/meet-purl-fosdem-2018/) - Identify and locate software packages using a simple yet expressive package URL. Meet purl at FOSDEM 2018 Conference. - [Panel discussion on the future of package management](https://nexb.com/package-management-fosdem-2018/) - Experts discuss what to expect for package management using FOSS tools. Panel discussion on the future of package management policies - [ScanCode: Open source scanning solution to identify licenses](https://nexb.com/scancode-floss-weekly-471/) - A development team can start scanning code on their own with ScanCode. ScanCode is a new open source scanning solution to identify the license(s) of the code. - [How much documentation for a software project?](https://nexb.com/open-source-answers-how-much-documentation-is-necessary/) - There is never enough documentation! Docs encourage users to discover more. Documentation is necessary. Docs encourage users to discover more. - [License Compliance is Like Saying Thank You for a Gift](https://nexb.com/license-compliance-the-new-stack/) - Lack of adherence to software licenses can lead to legal actions. Philippe offers help. License Compliance tools and technologies are like blessings! - [Making Sense of So Many License Compliance Tools](https://nexb.com/license-compliance-tools-fosdem-2019/) - A panel discussion on how FOSS tools for license compliance compare to proprietary tools. Available license compliance tools - [Importance of snippet matching for software provenance analysis](https://nexb.com/snippet-matching-for-software-provenance-analysis/) - Is snippet matching worth the resources involved for FOSS compliance? Snippet matching for software provenance analysis is import. - [Why is there no free software vulnerability database?](https://nexb.com/vulnerability-database-oss-summit-2020/) - Open data like FOSS code can improve application security with open tools and data for all. Vulnerability database should be free and open for all. - [Introducing FetchCode: A smart code downloader](https://nexb.com/fetchcode-pycon-india-2020-online/) - Give a URL, ANY URL or PURL and FetchCode will FETCH it as a universal and reliable library. FetchCode is a universal, smart code downloader library to fetch files from any HTTP, FTP, and VCS-based URL. - [Exploring the state of open source licensing clarity](https://nexb.com/open-source-licensing-clarity-opensuse-2020/) - Provenance and licensing of third-party software should be available as an open structured data. Provenance and licensing clarity of third-party software should be available as an open structured data. - [Building the FOSS security commons to identify vulnerabilities](https://nexb.com/foss-security-commons-opensuse-2020/) - We need a new approach for identifying FOSS vulnerabilities, using open data and FOSS tools. We need a FOSS security commons approach for identifying FOSS vulnerabilities, using open data and FOSS tools. - [FOSS & Third Party Software Compliance for Small Businesses](https://nexb.com/third-party-software-compliance-sfscon-2020/) - Planting seeds for blooming compliance and learn what is necessary to be compliant! FOSS & third-party software compliance for small organizations. - [Using Copyleft-licensed software components in a Java application](https://nexb.com/copyleft_licensed_software_java_app/) - Key considerations while using Copyleft-licensed software components in a Java application. Key considerations while using Copyleft-licensed software components in a Java application. - [nexB on GPL 3.0 and Related License Compliance Issues](https://nexb.com/gpl-3-0-license-compliance/) - The severity of Copyleft license-related issues depends on the context of OSS license policies. nexB on GPL 3.0 and related License Compliance Issues - [Updates on open source scanning with ScanCode](https://nexb.com/scancode-open-source-scanning-fosdem-2021/) - Best-in-class license, copyright and package manifest detection and data collection. - [Google Summer of Code: Open source SCA tools with AboutCode](https://nexb.com/google-summer-of-code/) - nexB is a mentor organization for student developers to work on open source development. Google Summer of Code, open source SCA tools with AboutCode - [Identifying packages and vulnerabilities across ecosystems](https://nexb.com/mostly-universal-purl-vers-dependencies-vulnerabilities/) - PURL and vers utilize a common language to identify FOSS packages and vulnerabilities. Utilizing a common language to identify FOSS packages and vulnerabilities. - [A vulnerability database should not be about vulnerabilities!](https://nexb.com/vulnerability-database-should-not-be-about-vulnerabilities/) - Lookup package vulnerabilities in an open database that aggregates them all with better accuracy! A comprehensive vulnerability database that aggregates most package ecosystems - [Scanning Docker images with ScanCode.io](https://nexb.com/scanning-docker-images-with-scancode-io/) - How to use ScanCode.io for Software Composition Analysis (SCA) with Docker images. Effective and efficient open source tool to scan Docker images - [Finding FOSS software vulnerabilities with FOSS tools](https://nexb.com/vulnerablecode-foss-software-vulnerabilities/) - VulnerableCode's benefit: better security of software applications with open tools and data for all. Finding FOSS software vulnerabilities with FOSS tools - [VulnerableCode v30 publicly available with new UI and API access](https://nexb.com/vulnerablecode-v30/) - VulnerableCode is as a free and open database of open source software package vulnerabilities. VulnerableCode v30 is now publicly available - [VulnerableCode: Find FOSS vulnerabilities, improve FOSS security](https://nexb.com/vulnerablecode-improves-foss-security/) - Automate finding FOSS component security vulnerabilities, using open data and FOSS tools. Automate finding FOSS vulnerabilities, using open data and FOSS tools. - [Providing Clarity on License Clarity Scoring in ScanCode](https://nexb.com/scancode-license-clarity-scoring/) - When automating SCA, License Clarity Scoring helps determine if scan results require more review. License Clarity Scoring helps determine if scan results require more review. - [There and back again: A software versioning story](https://nexb.com/software-versioning/) - With modern software development, a versioning convention is a key tool to manage software releases and revisions and implementing version control trivial - [VulnerableCode v31 expands vulnerability coverage](https://nexb.com/vulnerablecode-v31/) - VulnTotal cross-validates vulnerability coverage across other checking tools and databases. VulnTotal cross-validates the vulnerability coverage of VulnerableCode - [Do you really need to update the copyright statement each new year?](https://nexb.com/do-you-really-need-to-update-the-copyright-each-new-year/) - Developers update their project’s copyright notices at each new year, but why is it needed? A copyright statement with attribution and license is not only useful but necessary. - [VulnTotal: Validate vulnerability coverage of VulnerableCode](https://nexb.com/validate-vulnerablecode-vulnerability-coverage/) - Collate and cross-reference FOSS vulnerability data from multiple sources. VulnTotal validates vulnerability coverage of VulnerableCode - [Technical deep dive into VulnerableCode v31 and VulnTotal](https://nexb.com/technical-deep-dive-vulnerablecode-v31/) - Learn how to automate the search for FOSS security vulnerabilities, across many sources. VulnerableCode automates the search for FOSS security vulnerabilities, across many sources - [FOSDEM Recap: FOSDEM 2023 partial event report](https://nexb.com/fosdem-recap-2023/) - Avoid repeat work, establish automation to avoid re-running scans, share & reuse instead! - [What is a Dual License Anyway?](https://nexb.com/what-is-a-dual-license-anyway/) - Make it easier for users and remove the word “Dual” from your software project notice vocabulary. Best practices for dealing with dual license headache - [Track your software, and ensure compliance with DejaCode](https://nexb.com/dejacode-compliance/) - Use DejaCode to automate OSS license compliance and ensure software supply chain integrity. Use DejaCode to automate OSS license compliance. - [Standardizing FOSS package identifiers using PURL](https://nexb.com/standardizing-foss-package-identifiers-purl/) - Package-URL (PURL) is now the de-facto standard for the Software Composition Analysis community. PURL is now the de-facto standard for the Software Composition Analysis community. - [Tooling in software supply chain management](https://nexb.com/tooling-in-software-supply-chain-management/) - #post_excerptFOSS code is the essence of modern softwareTracking free and open source code across the software supply chain. - [Non-Vulnerable Dependency Resolution](https://nexb.com/non-vulnerable-dependency-resolution/) - Dependencies may come with vulnerabilities that can be exploited by attackers. Dependency resolution should be an an essential practice. Dependencies may come with vulnerabilities that can be exploited by attackers. - [Workshop on FOSS license and security compliance tools at FOSDEM](https://nexb.com/foss-license-and-security-compliance-tools-workshop-fosdem/) - #post_excerptOne-day workshop event before FOSDEM is to exchange ideas, share plans, and coordinate collaborations around FOSS tools - [Technical deep dive into VulnTotal](https://nexb.com/0207-vulntotal-deep-dive/) - Inspired by the VirusTotal multi-scanner virus scanning service, the VulnTotal project cross-validates the vulnerability coverage of VulnerableCode against other publicly available vulnerability check tools and databases. For instance, a package may be reported as vulnerable by one tool or database but not by another. We can gradually work with these tool providers to keep each other apprised about newly discovered vulnerabilities, making FOSS more secure.Join this webinar with the Linux Foundation's OpenChain Project to learn more about VulnTotal and VulnerableCode. VulnTotal project cross-validates the vulnerability coverage of VulnerableCode against other publicly available vulnerability check tools and databases. - [Deep dive into VulnerableCode v31](https://nexb.com/0209-vulnerablecode-v31/) - In this webinar, nexB CTO Philippe Ombredanne will demonstrate how to best use the FOSS tool to automate search for FOSS security vulnerabilities. An overall, deep dive into VulnerableCode v31. - [OpenChain Project Mini Summit](https://nexb.com/openchain-project-mini-summit/) - The OpenChain Project will host an afternoon mini-summit with a particular focus on: Open source tooling for open source compliance; Open source tooling for security assurance; Software bill of materials; The contribution OpenChain process standards make to business optimization and sustainability. There will be a special keynote about FOSSLight from LG Electronics, highlighting an emerging new tooling community that warrants attention. Our event will be heavy on toolchain landscapes, SBOM status and other mission-critical concerns. It will unpack trust management of the open source supply chain for OSPO, IP, product development and management teams. Expect a packed session with plenty of networking opportunities. OpenChain Project Mini Summit - [What the &#% Is in That SBOM? How to Provide Users What Software Components Are Included](https://nexb.com/oss-summit-north-america-2023/) - So you got an SBOM from a supplier. Now, what do you do with it?When you receive an SBOM from a supplier, the first challenge is to identify the components listed in that SBOM and map those components to your own component catalog and your relevant policies. A consistent system for identifying software components (package) is even more critical for managing the risk of software vulnerabilities because vulnerability data is a moving target spread across FOSS projects and repositories.In this talk at Open Source Summit North America 2023, Philippe will discuss utilizing the emerging open standard for Package URLs (PURLs) to standardize ingestion of incoming SBOMs and automate applying internal policies. He will then share how to best leverage VulnerableCode, as a public database of open vulnerability data based on PURLs, to track FOSS vulnerabilities and VEXs, all using FOSS tools and open data. SBOM challenges and tracking FOSS vulnerabilities using FOSS tools and open data. - [Open Source Software Supply Chain: FOSS for FOSS](https://nexb.com/securing-open-source-software-supply-chain-foss-for-foss/) - Software Composition Analysis is fundamental for open source software supply chain security. To make using open source easier, we need FOSS tools for FOSS SCA. - [Software Composition Analysis for Software Supply Chain Security](https://nexb.com/sboms-software-vulnerabilities/) - CEO Michael Herzog discusses the various SBOM specifications and Software Composition Analysis approaches for analyzing software vulnerabilities and licenses. - [Software Bill of Materials and Software Composition Analysis](https://nexb.com/software-bill-of-materials-sca/) - Defining, producing, and consuming Software Bill of Materials (SBOMs) are an integral part of Software Composition Analysis (SCA). - [SCA the FOSS Way – Part 1: Software Composition Analysis](https://nexb.com/software-composition-analysis/) - Software Composition Analysis (SCA) is a set of processes and tools to evaluate and manage software from a component perspective. - [ScanCode LicenseDB: 2,000+ licenses curated in a public database](https://nexb.com/curated-licenses-public-database-scancode-licensedb/) - ScanCode LicenseDB precisely identifies and organizes licenses and their metada. With over 2,000+ licenses curated in a public database. - [PURLs of Wisdom: Universal software package identification](https://nexb.com/purl-universal-software-package-identification/) - Accurately identify third-party software packages with PURL. The amount of code in a software package that can be identified by PURL depends on the environment. - [FOSS Daily for licensing "hygiene" and vulnerability compliance](https://nexb.com/foss-daily/) - Pay attention to your software – especially your open source components – as a daily habit. nexB team recommends for FOSS daily. - [Manage your organization's Usage Policies in DejaCode](https://nexb.com/usage-policies-in-dejacode/) - In DejaCode, you can define and enforce usage policies at license and component levels, and customize policies based on different needs and legal requirements. - [Python-inspector: Easily resolve Python dependencies](https://nexb.com/python-inspector-resolve-dependencies/) - Watch this recorded video to learn how to use Python-inspector to resolve Python dependencies without requiring additional builds and installs - [Practical License Detection for Organizations](https://nexb.com/practical-license-detection-for-organizations/) - Identify all licenses in a faster and cleaner process with minimal license detection exceptions. - [hack.lu 2023](https://nexb.com/hack-lu-2023/) - Hack.lu (and CTI summit) is an open convention/conference where people can discuss about computer security, privacy, information technology and its cultural/technical implication on society. - [NGI Forum 2023](https://nexb.com/ngi-forum-2023/) - The NGI Forum 2023 is the flagship event of the European Commission’s Next Generation Internet (NGI) initiative. It brings together some of Europe’s top Internet innovators at work to build an Internet of Trust, empowering end-users with more choice and control over their data and digital identity. ## Pages - [Homepage](https://nexb.com/) - Find open source and third-party components with ScanCode, automate FOSS compliance with DejaCode, and leverage nexB’s SCA expertise. - [SCA for Containers](https://nexb.com/sca-containers/) - Public Report: SCA for Containers Containers revolutionized the software development and deployment process. But there are still practical concerns, especially related to software supply chain integrity and security, that require improvement. Software Composition Analysis (SCA) identifies components used in software applications and systems, and detects their licensing and origin. SCA addresses software supply chain concerns - [VulnerableCode](https://nexb.com/vulnerablecode/) - [ScanCode](https://nexb.com/scancode/) - ScanCode is the most effective and efficient open source tool for Software Composition Analysis (SCA). - [DejaCode](https://nexb.com/dejacode/) - Track all components, automate open source compliance, and ensure software supply chain integrity. - [SaaS](https://nexb.com/saas/) - AboutCode as a Service makes ensuring open source compliance easier. Explore AboutCode SaaS Avoid hosting or infrastructure headache with AboutCode SaaS. Or we can run, operate, and maintain the integrated AboutCode stack – or select components – on your infrastructure or private cloud. Managed services are available for the complete AboutCode stack - [DejaCode.com Terms of Service](https://nexb.com/dejacode-com-tos/) - DejaCode.com Terms of Service 1. Acceptance of Terms nexB, Inc. (“nexB” or “us” or “we”) welcomes you to DejaCode.com and related sub-domains (“Sites”). These Terms of Service govern your use of our websites and all related forums, documentation, and other services you access through the websites (the “Service”). However, if you download software or purchase - [Contact Us](https://nexb.com/contact/) - [EULA](https://nexb.com/eula/) - nexB Inc. End User Agreement for Software as a Service READ THIS AGREEMENT CAREFULLY This Agreement is a legally binding agreement between you (meaning the person or the entity that obtained the Service under the terms and conditions of this Agreement and referred to below as “You” or “Customer”) and nexB (meaning nexB Inc.). You - [Support](https://nexb.com/support/) - Support open source compliance, and support the maintainers, with an AboutCode support plan. See plans Our mission is to make open source software safer and easier for everyone to use, with open source tools for open source SCA. By signing up for an AboutCode support plan, you ensure open source compliance and - [Videos](https://nexb.com/videos/) - Watch recorded conference talks and webinars on SCA, software licensing, FOSS compliance, and more. - [Privacy Policy](https://nexb.com/privacy/) - nexB cares about your right to privacy. This policy outlines how we collect, store, use, and disclose data. - [Services](https://nexb.com/services/) - Software Composition Analysis (SCA) services include due diligence and software audits for Software Bill of Materials (SBOM). - [Resources](https://nexb.com/resources/) - Read blog posts and watch recorded webinars on FOSS, compliance, SCA, nexB, and more. - [Credits](https://nexb.com/credits/) - [Terms of Use](https://nexb.com/terms-of-use/) - [Evaluation](https://nexb.com/evaluation/) - Ready to get started with DejaCode for open source compliance? Use your own data with a DejaCode private evaluation. - [About](https://nexb.com/about/) - At nexB, we are open source experts. ## My Templates - [contact us](https://nexb.com/?elementor_library=elementor-single-page-725) - Contact us to talk with an AboutCode expert! Fill out this form and we’ll get back to you right away. Looking for AboutCode community support? Chat with us on Slack Or chat on Gitter Submit a ticket via GitHub issues Read the docs You can also send us snail mail at: nexB Inc. 4966 El - [resources](https://nexb.com/?elementor_library=resources) - Resources on compliance, FOSS, AboutCode projects, SBOMs, SCA, and more. Read the AboutCode blog for insights on topics like Free and Open Source Software and Software Composition Analysis. Watch recorded videos to learn more about nexB software like ScanCode and DejaCode. Or explore our public DejaCode license library to see over 1,400 definitions of a - [site footer](https://nexb.com/?elementor_library=starter-kit-footer) - Know what’s in your software. Linkedin Twitter Youtube Github Software ScanCode VulnerableCode DejaCode Services Support SaaS Consulting Resources AboutCode Community Blog Documentation Videos Company About nexB Customers Careers FOSS Community Contact us © nexB Inc. All rights reserved. | Privacy Policy | Terms of Use | Credits - [home](https://nexb.com/?elementor_library=elementor-single-page-239) - We believe that good open source tools help you use open source. Visit AboutCode.org Get nexB support Our mission is to make open source software safer and easier for everyone to use, with open source tools for open source SCA. AboutCode is our community of critical open source tools for open source SCA – including - [services](https://nexb.com/?elementor_library=elementor-single-page-645) - We can help you find and fix open source compliance problems, quickly. nexB offers comprehensive consulting services, including Software Composition Analysis (SCA) audits for acquisition or investment due diligence or for your own products, along with implementation services for the AboutCode stack. With over 15 years of experience providing SCA services to organizations of all - [Elementor Single Page #2085](https://nexb.com/?elementor_library=elementor-single-page-2085) - Privacy Policy Last updated: May 2024 nexB Inc. (“nexB”, “we”, “our” or “us”) cares about your right to privacy. This policy outlines how we collect, store, use, and disclose the following types of data: Visitor data includes individuals (“Visitors”) who visit our websites. Prospect data includes individuals (“Prospects”) who have shared their email address with - [terms of use](https://nexb.com/?elementor_library=elementor-single-page-801) - Terms of Use Acceptance of Terms nexB Inc. (“nexB” or “us” or “we”) owns and operates the website at nexB.com (the “Website”). These Website Terms of Use govern all access to and use of the Website and constitute a binding legal agreement. Please read this Website Terms of Use and our Website Privacy Policy at - [support](https://nexb.com/?elementor_library=support) - Support open source compliance, and support the maintainers, with an AboutCode support plan. See plans Our mission is to make open source software safer and easier for everyone to use, with open source tools for open source SCA. By signing up for an AboutCode support plan, you ensure open source compliance and software supply chain - [dejacode](https://nexb.com/?elementor_library=elementor-single-page-639) - Track all components, ensure compliance. DejaCode is an open source, complete enterprise-level application to automate open source license compliance and ensure software supply chain integrity, powered by ScanCode, the industry-leading code scanner. Track all components, ensure compliance. DejaCode is a complete enterprise-level application to automate open source license compliance and ensure software supply chain integrity, powered - [services](https://nexb.com/?elementor_library=services) - We can help you find and fix any compliance problems, quickly.​ nexB offers comprehensive Software Composition Analysis (SCA) services, ranging from a full-service approach for acquisition or investment due diligence to a product-baseline software audit for evaluating a Software Bill of Materials (SBOM) from your engineering team or a supplier. With over twelve years of - [main site header](https://nexb.com/?elementor_library=elementor-header-61) - Try DejaCode - [post header](https://nexb.com/?elementor_library=post-header) - Share ➜ Sign in to DejaCode - [blog post v2](https://nexb.com/?elementor_library=elementor-single-post-7512) - Related posts Ensuring software license compliance can be difficult. We can help. Start scanning your code with ScanCode Automate FOSS compliance with DejaCode Contact us for help with any questions - [Elementor Loop Item #7412](https://nexb.com/?elementor_library=elementor-loop-item-2) - [video loop](https://nexb.com/?elementor_library=video-container-loop-item-6289) - [blog archive template](https://nexb.com/?elementor_library=elementor-archive-346) - Read about open source, SBOMs, licensing, SCA, and compliancefrom the nexB team. Ensuring software license compliance can be difficult. We can help. Start scanning your code with ScanCode Automate FOSS compliance with DejaCode Contact us for help with any questions - [Custom](https://nexb.com/?elementor_library=custom) - [future-cta](https://nexb.com/?elementor_library=future-cta) - Open source for open source. Ensure enterprise-wide compliance, and automate with DejaCode. Get started for free Learn more about DejaCode - [about](https://nexb.com/?elementor_library=elementor-single-page-737) - At nexB, we are open source experts. nexB was founded in 2003 by Michael J. Herzog, Philippe Ombrédanne, and François Granade. Our mission is to provide software and services to enable companies and other organizations to effectively leverage open source software and also to actively comply with the conditions of open source licenses. Our conclusion - [evaluation](https://nexb.com/?elementor_library=elementor-single-page-788) - Use your own data with a DejaCode private evaluation Ready to get started with DejaCode? Please complete this form so we can set up your free 30-day private evaluation. Each DejaCode private evaluation includes: A private instance of DejaCode Unlimited use of DejaCode Unlimited number of users and products Free technical support Easy access from - [video post template](https://nexb.com/?elementor_library=blog-post-template-copy) - Share on LinkedIn Share on Twitter Share via Email Share on Reddit More videos Ensuring software license compliance can be difficult. We can help. Start scanning your code with ScanCode Automate FOSS compliance with DejaCode Contact us for help with any questions - [blog post template](https://nexb.com/?elementor_library=elementor-single-post-288) - Share on LinkedIn Share on Twitter Share via Email Share on Reddit Related posts Ensuring software license compliance can be difficult. We can help. Start scanning your code with ScanCode Automate FOSS compliance with DejaCode Contact us for help with any questions - [event loop](https://nexb.com/?elementor_library=elementor-loop-item) - Register Register - [featured blog post loop](https://nexb.com/?elementor_library=elementor-featured-blog-loop-item-6212) - [blog archive loop](https://nexb.com/?elementor_library=elementor-loop-item-6218) - [webinar registration](https://nexb.com/?elementor_library=elementor-single-post-3077) - Sign up now - [vulnerablecode](https://nexb.com/?elementor_library=elementor-single-page-2329) - Find FOSS vulnerabilities,improve FOSS security. VulnerableCode is a FOSS tool to automate search for FOSS security vulnerabilities. By collecting and parsing data from many sources, identifying packages using a standardized package-url, and accessing the data through a REST API, VulnerableCode addresses key security concerns for using FOSS code in modern applications. Find FOSS vulnerabilities,improve FOSS - [scancode](https://nexb.com/?elementor_library=elementor-single-page-1120) - Find open source with open source, with ScanCode. ScanCode is the most effective and efficient open source tool for Software Composition Analysis (SCA), used and trusted by the Linux kernel maintainers as a code scanning engine. Add ScanCode Toolkit to your workflow directly or connect ScanCode.io with comprehensive APIs. Find open source with open source, with - [footer-cta](https://nexb.com/?elementor_library=footer-cta) - Ensuring software license compliance can be difficult. We can help. Start scanning your code with ScanCode Automate FOSS compliance with DejaCode Contact us for help with any questions - [webinar loop](https://nexb.com/?elementor_library=webinar_loop) - Register - [Elementor Single Page #807](https://nexb.com/?elementor_library=elementor-single-page-807) - Open Source Credits [table id=1 automatic_url_conversion=true responsive=scroll responsive_breakpoint=”phone” /] - [video loop](https://nexb.com/?elementor_library=video-loop) - [blog post archive loop](https://nexb.com/?elementor_library=elementor-loop-378) - [featured blog post loop](https://nexb.com/?elementor_library=elementor-loop-518) - [webinar](https://nexb.com/?elementor_library=webinar2) - [webinar registration](https://nexb.com/?elementor_library=webinar-registration) - [Elementor Error 404 #71](https://nexb.com/?elementor_library=elementor-error-404-71) - 404 You’re in the right place! Just the wrong page… Back to Home You can also use the menu above or footer below to find which way you go to get on out of here. 404 You’re in the right place! Just the wrong page… Back to Home You can also use the menu above - [content](https://nexb.com/?elementor_library=content) - Why is software compositionanalysis important? BLOG Why are software audits important? Because we say so. And because you probably don’t want to get sued because you misused licenses or misattributed code. Read WHITEPAPER Gartner identifies nexB as leader for SCA Download COMPUTER MAGAZINE (OCT 2020) FOSS License Compliance: Tools for Software Composition Analysis Read LICENSE - [content](https://nexb.com/?elementor_library=content-2) - Why is open source software license compliance important? BLOG Best Practices for OSS Attribution Open source attribution obligations, as specified in the most common licenses, are usually very simply stated, and subject to a great deal of interpretation. Read COMPUTER MAGAZINE (OCT 2020) FOSS License Compliance: Tools for Software Composition Analysis Read THE NEW STACK - [users](https://nexb.com/?elementor_library=users-2) - To understand what’s in their software,companies of all sizes choose nexB - [Elementor Single Page #2385](https://nexb.com/?elementor_library=elementor-single-page-2385) - TESTING1 - [Elementor Archive #2164](https://nexb.com/?elementor_library=elementor-archive-2164) - Videos Watch recorded talks on open source, compliance, and more from the nexB team Ensuring software license compliance can be difficult. We can help. Contact us Ready to start scanning your code? Run ScanCode Need to automate FOSS compliance? Try DejaCode - [dejacode register mockup](https://nexb.com/?elementor_library=dejacode-register-mockup) - Explore DejaCode now A free DejaCode account allows you to use almost all of DejaCode! The main limitation is the ability to import your own data privately. When you sign in to the free DejaCode dataspace, you can: Explore, create, and modify components, packages, licenses and assign usage policies to them. Create your own test products - [Default Kit](https://nexb.com/?elementor_library=default-kit) - [scancode_old](https://nexb.com/?elementor_library=elementor-single-page-630) - Discover open source components with ScanCode The most effective and efficient open source tool for Software Composition Analysis (SCA). Learn more Get started Industry-leading code scanner Identify licenses, copyrights, dependencies and other origin clues directly from your codebase with ScanCode Toolkit. The Linux kernel maintainers use ScanCode Toolkit as a scanning engine. Supporting all programming - [test](https://nexb.com/?elementor_library=test) - [Elementor Single Page #635](https://nexb.com/?elementor_library=elementor-single-page-635) - What’s in your software? Many organizations do not know what other software is really in their software! nexB provides Software Composition Analysis services, including acquisition due diligence and product audits. Learn more Request quote Open Source Software Audits For Modern Products and Businesses What’s in your software? Many organizations do not know what other software - [Elementor Single Page #234](https://nexb.com/?elementor_library=elementor-single-page-234) - What’s in your software? Many organizations do not know what other software is really in their software! nexB provides Software Composition Analysis services, including acquisition due diligence and product audits. Learn more Request quote Open Source Software Audits For Modern Products and Businesses What’s in your software? Many organizations do not know what other software - [Elementor Single Page #103](https://nexb.com/?elementor_library=elementor-single-page-103) - What’s in your software? Today’s fastest growing companies use DejaCode to automate open software compliance and management, and choose nexB for their software audit services. Get Started Components have detailed metadata including origin, version, license, technology, and functionality. Complete with a library of open source and proprietary licenses with detailed documentation of license terms and - [Elementor Single Page #79](https://nexb.com/?elementor_library=elementor-single-page-79) - WHAT’s inyour software? Get Started ACCELERATE SOFTWARE DEVELOPMENT Use the best open source and third-party software components for your products. Comprehensive software license library with clear definition of obligations and restrictions Extensible license definitions and annotations Software BOM tracking for all your products for a comprehensive view of all components used in your software Powerful ## Categories - [AboutCode](https://nexb.com/category/aboutcode/) - [Open Source](https://nexb.com/category/open-source/) - [Upcoming](https://nexb.com/category/upcoming/) - [Webinar](https://nexb.com/category/webinar/) - [Conference](https://nexb.com/category/conference/) - [Video](https://nexb.com/category/video/) - [Past](https://nexb.com/category/past/) ## Tags - [Snippet](https://nexb.com/tag/snippet/) - [Open Source](https://nexb.com/tag/open-source/) - [Compliance](https://nexb.com/tag/compliance/) - [Software Audit](https://nexb.com/tag/software-audit/) - [Snippet Matching](https://nexb.com/tag/snippet-matching/) - [Copyleft](https://nexb.com/tag/copyleft/) - [License Java](https://nexb.com/tag/license-java/) - [Jar](https://nexb.com/tag/jar/) - [Software Licensing](https://nexb.com/tag/software-licensing/) - [Library](https://nexb.com/tag/library/) - [Webinar](https://nexb.com/tag/webinar/) - [Conference](https://nexb.com/tag/conference/) - [The New Stack](https://nexb.com/tag/the-new-stack/) - [FOSDEM 2019](https://nexb.com/tag/fosdem-2019/) - [OSS Summit 2020](https://nexb.com/tag/oss-summit-2020/) - [PyCon India 2020](https://nexb.com/tag/pycon-india-2020/) - [openSUSE 2020](https://nexb.com/tag/opensuse-2020/) - [SFScon 2020](https://nexb.com/tag/sfscon-2020/) - [FOSDEM 2021](https://nexb.com/tag/fosdem-2021/) - [FLOSS Weekly](https://nexb.com/tag/floss-weekly/) - [FOSDEM 2018](https://nexb.com/tag/fosdem-2018/) - [Open Source Summit](https://nexb.com/tag/open-source-summit/) - [OpenChain](https://nexb.com/tag/openchain/) - [nexB](https://nexb.com/tag/nexb/) - [NLnet Foundation](https://nexb.com/tag/nlnet-foundation/) - [PyDelhi 2023](https://nexb.com/tag/pydelhi-2023/)