a repository scanner that has a significant breadth of assessments
519
trustsource/ts-deepscan
Command-line repository/dependency scanner for open source compliance. DeepScan clones or scans a local directory and analyses every contained file for:
minr), locally or against the SCANOSS knowledge base--include-yara)Results are written as structured JSON, can be exported as SPDX/CycloneDX SBOMs, or uploaded directly to TrustSource for policy evaluation. Supports 30+ source languages.
docker run --rm -v "$(pwd)":/scan trustsource/ts-deepscan \
scan -o /scan/results.json /scan
Version 2.4.1 · Apache-2.0 Maintained by EACG GmbH · github.com/trustsource/ts-deepscan · docs
DeepScan is also available as part of the subscription-based TrustSource platform — the process-focused open source compliance tool covering the full OSS compliance toolchain.
Content type
Image
Digest
sha256:2eecd1cae…
Size
622 MB
Last updated
8 months ago
docker pull trustsource/ts-deepscan