Skip to content
Back to the index

FOSSA

fossa.comApplication security & vulnerability scanning🇺🇸

No liveness check has reached it yet; it has been in the index since 9 Oct 2026. How this is checked

FOSSA helps development and security teams scan third-party code, containers, binaries, and dependencies for license and vulnerability risks. It automates SBOM generation, regulatory reporting, dependency updates, and software supply-chain compliance.

Inferred · not functionally tested

EnterpriseWebCloud-managedCLIAPI
FOSSA preview
Visit fossa.com

Overview

6 features

Purpose: Managing open-source license risk, software vulnerabilities, and SBOM compliance across the software development lifecycle.

Inferred · not functionally tested

Audience: software development and security teams

Inferred · not functionally tested

Functions: monitoring, workflow_automation, data_extraction

Inferred · not functionally tested

Interfaces: API: indicated (inferred, not tested) · MCP: unknown · CLI: indicated (inferred, not tested) · Self-hosting: unknown

Recorded constraints: pricing: enterprise_only · license: Proprietary · platforms: WEB · deployment: browser, cloud_managed, cli, api_only

Constraint provenance is unknown; confirm requirements with the publisher.

Record sources: fossa.com. These links do not verify the individual claims.

FOSSA sits in PulseGate's Application security & vulnerability scanning category. Inferred · not functionally tested: It focuses on managing open-source license risk, software vulnerabilities, and SBOM compliance across the software development lifecycle. Inferred · not functionally tested: It is built as a B2B product for software development and security teams. Basis unknown · not verified: Pricing is enterprise-only. Basis unknown · not verified: It runs on the web, the command line, and API.

It is developed by FOSSA, Inc. (United States). Inferred · not functionally tested: Among its 6 catalogued features are dependency scanning, SBOM generation, and license compliance. Inferred · not functionally tested: Catalogued interfaces include a public API.

Summary written by a language model from the project’s public pages.

Tasks: Inferred · not functionally tested

  • Dependency scanning
  • SBOM generation
  • License compliance
  • Vulnerability management
  • Container scanning
  • Binary scanning

Topics: Inferred · not functionally tested

Tags
software-composition-analysissbom-managementlicense-compliancedependency-securityvulnerability-management
AI capabilities
Text
Inference: Cloud API

JSON profile · Text profile · Access guide

Built with & integrations

Framework
Next.js
Hosting
VercelAWS
Connectors
APIgithubgitlabslackwebhook
Runs on
BrowserCloud-managedCLIAPI-only
Detected from
AWS
x-amz-cf-id header · x-amz-cf-pop header · via header
Next.js
x-nextjs-prerender header · /_next/static/ in the HTML
Vercel
x-vercel-id header · x-vercel-cache header

Trust & compliance

Public signals
HTTPS

Indexing history

1

What PulseGate has recorded for this listing

  1. Indexed8 Oct · 19:57 UTC
    Fossa seen via Saashub
    Source: Saashub · Open

Frequently asked questions about FOSSA

What does FOSSA do?
Inferred · not functionally tested: FOSSA focuses on managing open-source license risk, software vulnerabilities, and SBOM compliance across the software development lifecycle. It is catalogued under Application security & vulnerability scanning on PulseGate.
Who is FOSSA for?
Inferred · not functionally tested: FOSSA is a B2B product built for software development and security teams.
Is FOSSA free?
Basis unknown · not verified: No — FOSSA is sold on an enterprise-only basis.
What platforms does FOSSA run on?
Basis unknown · not verified: FOSSA runs on the web, the command line, and API.
Is FOSSA still active?
Unverified. FOSSA has not been re-checked since it entered the index, so there is no finding either way — and only a positive finding would say otherwise.
What are alternatives to FOSSA?
Similar projects tracked by PulseGate include Bravos, SBOM Tool, and nti-scanner.BravosSBOM Toolnti-scanner
Who develops FOSSA?
FOSSA is developed by FOSSA, Inc., based in the United States.
Does FOSSA have an API or integrations?
Inferred · not functionally tested: Yes — FOSSA exposes a public API.

Also in Application security & vulnerability scanning

Same category — not a similarity match