Project Setup
Get your code into FOSSA — import projects from source hosts, the CLI, or CI, then configure how they're scanned and organized.
Overview
Before FOSSA can flag a license obligation or a vulnerability, it needs to know what's actually in your software. Project setup is how you get that dependency data in.
FOSSA meets your code where it lives, but the methods aren't equal. Running the CLI in your build sees the same dependency graph your package manager resolves (including transitive and build-time dependencies) so it's the most accurate and complete picture FOSSA can get. Wiring that into CI/CD keeps every project current automatically and gates risky changes before they merge. That's the path we recommend for any project you care about.
Tip
Run fossa analyze as a step in your CI/CD pipeline. You get the most accurate results, automatic re-scans on every build, and PR checks that catch new risk before it merges, without granting FOSSA access to your source.
archive-upload
automatic-updates
badge-pull-requests
binaries
broker
build-history
cicd-scanning
cli
containers
dependencies
ignore-a-dependency
issue-scanners
mediated-dependencies
notifications
package-inventory
pr-checks
privacy-settings
project-labels
project-settings
quick-import
sbom-import
scan-frequency
snippets
Choose your import method
| If you want to… | Use | How it works |
|---|---|---|
| Get the most accurate results, or avoid giving FOSSA code access | CLI | Analyze locally or in CI; upload only dependency signatures |
| Keep every project current and gate risky changes | CI/CD scanning | Run the CLI in your pipeline with PR checks |
| Analyze container images | Containers | fossa container analyze on Docker or OCI images |
| Find open source copied into your own code | Snippets | CLI fingerprinting that surfaces undeclared open source |
| Analyze a binary without its source | Binaries | Upload a compiled artifact for decomposition · Enterprise |
| Analyze components from an existing SBOM | SBOMs | Upload a CycloneDX or SPDX document · Enterprise |
| Get broad, low-effort coverage to start | Quick Import | Connect your VCS; FOSSA pulls and analyzes the code |
Scan with the FOSSA CLI
The FOSSA CLI analyzes your build and uploads only dependency signatures, the most accurate and secure path, and the right choice whenever you can grant FOSSA a place in your build.
- CLI: run
fossa analyzeagainst your build for full dependency analysis. - CI/CD scanning: run that analysis automatically on every build, with PR checks that gate merges.
- Containers: scan Docker and OCI container images for license and vulnerability issues.
- Snippets: detect open source code copied into your first-party source, and the obligations it carries.
Quick Import, broad coverage, fast
When you need coverage across many repositories with minimal setup, Quick Import connects GitHub, GitLab, Bitbucket, or Azure Repos and analyzes your repositories directly, wiring up webhooks and scheduled re-scans. It's the fastest way to get started and FOSSA never writes to your code, but because it analyzes source without running your build, its results are less complete than a CLI scan. Treat it as a quick start or a fallback for projects you can't put in CI, and move your important projects to the CLI when you can.
Behind a firewall? Broker imports repositories from Bitbucket Server, on-prem GitLab, or GitHub Enterprise without sharing source-code access.
Upload an artifact
When you have a built artifact but not its source, hand it to FOSSA directly:
- Binaries: decompose pre-compiled binaries and archives to identify the open source inside. (Enterprise)
- SBOMs: bring in an existing CycloneDX or SPDX SBOM and run compliance checks against its components. (Enterprise)
Configure and organize
Once a project is imported, you control how it's scanned: the build and analysis method, which targets are included, scan scheduling, and project-level settings. Use Release Groups to bundle related projects and revisions for shared reporting and policy enforcement.
From here, your data flows into Licenses, Vulnerabilities, Quality, and SBOM.