Supported Ecosystems & Tools

fossabot's support for language ecosystems varies based on our automated testing and availability of ground truth/evaluation dataset coverage.

Ecosystem NameDependency ReviewDependency PR CreationSAST Review
Javascript/TypescriptStrong/Well-supportedStrong/Well-supportedStrong/Well-supported
Java (Kotlin)Strong/Well-supportedStrong/Well-supportedStrong/Well-supported
PythonBeta qualityNot supportedStrong/Well-supported
Go (Golang)Beta qualityNot supportedStrong/Well-supported
RubyBeta qualityNot supportedStrong/Well-supported
RustBeta qualityNot supportedStrong/Well-supported
ClojureAlpha qualityNot supportedStrong/Well-supported
DartAlpha qualityNot supportedNot supported
ElixirAlpha qualityNot supportedStrong/Well-supported
ErlangAlpha qualityNot supportedNot supported
FortranAlpha qualityNot supportedNot supported
HaskellAlpha qualityNot supportedNot supported
iOS (Objective-C, Swift)Alpha qualityNot supportedStrong/Well-supported
.NET (C#, F# VB)Alpha qualityNot supportedStrong/Well-supported
PHPAlpha qualityNot supportedStrong/Well-supported
PerlAlpha qualityNot supportedNot supported

Configuring a Private Registry/Code Mirror

fossabot installs your application's full dependency tree and requires access to all dependencies, both public and private.

NPM-style Code Mirrors

Credentials to an "npm-style" code mirror can be configured in Organization Settings. Common examples of this are Artifactory, GitHub Package Registry, and NPM's native private packages.

Maven Code Mirrors

Credentials to a Maven-style code mirror can be configured in Organization Settings. Common examples of this are Artifactory, Sonatype Nexus, and GitHub Packages for Maven.