FOSSA CLI

Analyze dependencies, test policies, and generate reports from the command line.

1 min readUpdated Sep 22, 2026

Overview

The FOSSA CLI analyzes your project's dependencies from the command line, on your machine or in CI, and uploads the results to FOSSA for license, security, and quality analysis. For most projects it works with zero configuration: install the CLI, set your API key, and run fossa analyze.

Because it reads dependencies straight from your build, the CLI is the most accurate way to get a project into FOSSA. See Project Setup for how it compares to Quick Import and the other import methods, and CI/CD scanning to run it automatically on every build.

These docs are organized into Concepts (how analysis works), Walkthroughs (step-by-step integration guides), Features (specific capabilities like container and vendored-dependency scanning), and References (every command, configuration file, and troubleshooting guide). Browse them below or from the sidebar. Not sure what the CLI sends to FOSSA? See what data gets uploaded.

© 2026 FOSSA, Inc.support@fossa.com