Skip to content
Notifications
Clear all

What to use instead of FOSSA for dependency scanning in 2025?

1 Posts
1 Users
0 Reactions
35 Views
(@data_pipeline_tinker)
Honorable Member
Joined: 5 months ago
Posts: 364
Topic starter   [#18579]

As we move into 2025, the landscape for open source license compliance and dependency scanning continues to evolve rapidly. While FOSSA has been a prominent player, several teams—including my own—are reevaluating their toolchain, seeking more granular control, better integration with existing data pipelines, or more predictable cost structures. The core need remains: we must ingest Software Bill of Materials (SBOM) data, transform it into actionable insights, and load it into our compliance and security dashboards. It's an ETL problem at its heart.

Based on recent evaluations and community discussions, here are the primary alternatives I've been testing, categorized by their operational model and integration potential.

**Pipeline-Integrated Scanners (My Preferred Approach)**

These tools act as components within a broader data pipeline, allowing you to treat scan results as datasets.

* **ScanCode Toolkit / scancode.io:** This is the engine powering many commercial offerings. Running ScanCode directly, while resource-intensive, provides the most raw data. You can orchestrate it via Airflow or Dagster, outputting results in JSON, SPDX, or CycloneDX for later transformation with dbt.
```bash
# Example of generating raw data for later processing
scancode -clpieu --json-pp /tmp/output.json /path/to/project
```
The resulting JSON can be loaded into BigQuery for complex policy SQL queries.

* **ORT (OSS Review Toolkit):** A highly configurable suite from the Linux Foundation. Its key advantage is the clear separation of phases: download, analyze, scan, report. You can plug in different scanners (e.g., ScanCode, Licensee) and export to multiple formats. It's ideal for teams wanting to build a custom review pipeline.
```yaml
# ort.yml config snippet defining the analyzer
analyzer:
enabled: true
allow_dynamic_versions: false
```

**Managed & SaaS Platforms**

These offer a more complete, out-of-the-box experience but with less pipeline flexibility.

* **Mend (formerly WhiteSource) / Snyk Open Source:** These have expanded beyond vulnerability scanning into deep license analysis. Their APIs are robust, enabling you to extract findings and load them into your warehouse. However, the transformation logic is often locked within their UI.
* **DependencyTrack / CycloneDX:** This is a powerful paradigm shift. Instead of a scanner, it's an SBOM analysis platform. You generate standards-compliant SBOMs (using Syft, Trivy, or the tools above) and upload them. All policy evaluation happens centrally. This decouples the scan from the analysis, fitting nicely into a modular pipeline.

**Critical Considerations for 2025**

When comparing these to FOSSA's model, pay close attention to:

* **SBOM Format Support:** Ensure your chosen tool ingests and outputs SPDX and/or CycloneDX. This is your vendor-agnostic lifeline.
* **CI/CD Integration Pattern:** Does it require an agent, a CLI, or just an API call? This dictates your pipeline orchestration.
* **Data Enrichment Workflow:** How are license texts and copyrights matched? Is the logic transparent?
* **Cost Drivers:** Is it per repository, per scan, per developer seat, or per volume of data processed? This significantly impacts scaling.

In my current setup, I'm prototyping a two-stage pipeline: using ORT to generate a CycloneDX SBOM, enriching it with internal data via a dbt model, and then pushing it to DependencyTrack for policy evaluation and dashboarding. This provides the data control I need while leveraging a specialized analysis engine. I'm curious what patterns others are exploring, especially regarding the transformation layer between the raw scan and the policy engine.


Extract, transform, trust


   
Quote