Skip to main content

[Korean]

FOSSLight Scanner

Analyze at once for Open Source Compliance.

FOSSLight Scanner license: Apache-2.0 Current python package version REUSE status Guide

FOSSLight Scanner performs open source analysis after downloading the source by passing a link that can be cloned by wget or git. Instead, open source analysis can be performed for the local source path. The output result is generated in FOSSLight Report format.

Contents

Please refer to https://fosslight.org/fosslight-guide/scanner/ for the FOSSLight Scanner User Guide.

📋 Prerequisite

FOSSLight Scanner needs a Python 3.10+.

🎉 How to install

It can be installed using pip3. It is recommended to install it in a virtualenv environment.

pip3 install fosslight_scanner

🚀 How to run

FOSSLight Scanner is run with the fosslight command.

fosslight [Mode] [option1] <arg1> [option2] <arg2>...

Parameters

Mode

        all                     Run all scanners(Default)
        source                  Run FOSSLight Source
        dependency              Run FOSSLight Dependency
        binary                  Run FOSSLight Binary
        compare                 Compare two FOSSLight reports

Options:

        -h                      Print help message
        -p <path>               Path to analyze (ex, -p {input_path})
                                 * Compare mode input file: Two FOSSLight reports (supports excel, yaml)
                                   (ex, -p {before_name}.xlsx {after_name}.xlsx)
        -w <link>               Link to be analyzed can be downloaded by wget or git clone
        -f <format>             FOSSLight Report file format (excel, yaml)
                                 * Compare mode result file: supports excel, json, yaml, html
        -o <output>             Output directory or file
        -c <number>             Number of processes to analyze source
        -e <path>               Path to exclude from analysis (files and directories, pattern matching is available)
                                 * IMPORTANT: Always wrap patterns in quotes("") to avoid shell expansion.
                                   Example) fosslight -e "test/abc.py" "*.jar" "test/"
        -r                      Keep raw data
        -t                      Hide the progress bar
        -v                      Print FOSSLight Scanner version
        -s <path>               Path to apply setting from json file (check format with 'tests/fixtures/setting.json' in this repository)
                                 * Direct cli flags have higher priority than setting file
                                   (ex, '-f yaml -s tests/fixtures/setting.json' - result file extension is .yaml)
  • Refs.
  • Pattern matching guide for the -e option
    • ⚠️ Make sure to use double quotes ("") when entering values.
      • Example) fosslight -e "test/abc.py" "*.jar" "test/"
    • ⚠️ File names and extensions are case-sensitive, so please enter them exactly as intended.

Ex 1. Local Source Analysis

fosslight all -p /home/source_path -d "-a 'source /test/Projects/venv/bin/activate' -d 'deactivate'"

If using additional flags like -d, document them in Options section or link to related guide.

Ex 2. Local Source Analysis with Path to Exclude

fosslight all -p /home/source_path -e "temp_dir" "src/temp.py"
fosslight all -o test_result_wget -w "https://github.com/LGE-OSS/example.git"

If you want to analyze private repository, set your GitHub token like below.

fosslight all -w "https://my_github_token@github.com/Foo/private_repo"

Ex 4. Compare the BOM of two FOSSLight reports

fosslight compare -p FOSSLight_before_proj.yaml FOSSLight_after_proj.yaml -f excel

📁 Result

$ tree
.
├── fosslight_log
│   ├── fosslight_log_20210924_022422.txt
└── FOSSLight-Report_20210924_022422.xlsx
  • FOSSLight_Report-[datetime].xlsx: OSS Report format file that outputs source code analysis, binary analysis, and dependency analysis results.
  • fosslight_raw_data_[datetime] directory: Directory in which raw data files are created as a result of analysis

🐳 How to run using Docker

  1. Build image using Dockerfile.
docker build -t fosslight .
  1. Run with the image you built.
    ex. Output: /Users/fosslight_source_scanner/test_output, Path to be analyzed: tests/test_files
docker run -it -v /Users/fosslight_source_scanner/test_output:/app/output fosslight -p tests/test_files -o output

👏 How to report issue

Please report any ideas or bugs to improve by creating an issue in fosslight_scanner repository. Then there will be quick bug fixes and upgrades. Ideas to improve are always welcome.

👏 Contributing Guide

We always welcome your contributions. Please see the CONTRIBUTING guide for how to contribute.

📄 License

FOSSLight Scanner is released under Apache-2.0.

Metadata

Release files for fosslight-scanner 2.1.32

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for fosslight-scanner 2.1.32
File Size Uploaded
fosslight_scanner-2.1.32.tar.gz 35.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for fosslight-scanner 2.1.32
File Interpreter ABI Platform
fosslight_scanner-2.1.32-py3-none-any.whl Python 3 none any Details

Total release size: 63.7 kB

Release files / fosslight_scanner-2.1.32.tar.gz

Download URL fosslight_scanner-2.1.32.tar.gz
Size 35.5 kB
Tags Source
SHA-256 checksum
How to use checksums
5b92e26cbce28c99a573074d1c0a78f78f9ab5b3ffd02d1fbed04efe517f8f08
BLAKE2b-256 checksum
How to use checksums
4816bb398322b1f7be5f8efb710b1204b8f1baa986255be101334bb89ed2c38f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.14

Release files / fosslight_scanner-2.1.32-py3-none-any.whl

Download URL fosslight_scanner-2.1.32-py3-none-any.whl
Size 28.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
5273a6bcf6aa1edfcc27aadb4f01cca03c5093e9b732794d4a05abb01424888a
BLAKE2b-256 checksum
How to use checksums
268dd0ce5396c0a2dc7b33f4d3c4043406777632c02a30ab8c682e320c345aec
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.14

Release history Release notifications | RSS feed

This release

2.1.32 This release

2 release files

2.1.31

2 release files

2.1.30

2 release files

2.1.29

2 release files

2.1.27

2 release files

2.1.25

2 release files

2.1.20

2 release files

2.1.19

2 release files

2.1.18

2 release files

2.1.15

2 release files

2.1.14

2 release files

2.1.13

2 release files

2.1.12

2 release files

2.1.11

2 release files

2.1.10

2 release files

2.1.9

2 release files

2.1.8

2 release files

2.1.7

2 release files

2.1.6

2 release files

2.1.5

2 release files

2.1.4

2 release files

2.1.3

2 release files

2.1.2

2 release files

2.1.1

2 release files

2.1.0

2 release files

2.0.1

2 release files

2.0.0

2 release files

1.7.30

2 release files

1.7.27

2 release files

1.7.26

2 release files

1.7.24

2 release files

1.7.23

2 release files

1.7.22

2 release files

1.7.20

2 release files

1.7.19

2 release files

1.7.16

2 release files

1.7.15

2 release files

1.7.14

2 release files

1.7.13

2 release files

1.7.11

2 release files

1.7.10

2 release files

1.7.9

2 release files

1.7.8

2 release files

1.7.7

2 release files

1.7.6

2 release files

1.7.5

2 release files

1.7.4

2 release files

1.7.3

2 release files

1.7.2

2 release files

1.7.1

2 release files

1.7.0

2 release files

1.6.14

2 release files

1.6.13

2 release files

1.6.12

2 release files

1.6.11

2 release files

1.6.10

2 release files

1.6.9

2 release files

1.6.8

2 release files

1.6.7

2 release files

1.6.6

2 release files

1.6.5

2 release files

1.6.4

2 release files

1.6.3

2 release files

1.6.2

2 release files

1.6.1

2 release files

1.6.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page