Sign inSign up

trustsource/ts-deepscan

By trustsource

•Updated 8 months ago

a repository scanner that has a significant breadth of assessments

Image
Security
Integration & delivery
Developer tools
0

519

trustsource/ts-deepscan repository overview

⁠TrustSource DeepScan

trustsource/ts-deepscan

Command-line repository/dependency scanner for open source compliance. DeepScan clones or scans a local directory and analyses every contained file for:

  • License identification — SPDX tag detection plus similarity matching against known license texts to determine effective licenses
  • Copyright statements — extracted from source comments and LICENSE/COPYING/README files (via ScanCode)
  • Cryptographic algorithm usage — detects known encryption/hash implementations in source files (via SCANOSS minr), locally or against the SCANOSS knowledge base
  • Malware indicators — optional YARA-based scanning of files or whole directories (--include-yara)

Results are written as structured JSON, can be exported as SPDX/CycloneDX SBOMs, or uploaded directly to TrustSource⁠ for policy evaluation. Supports 30+ source languages.

⁠Quick start

docker run --rm -v "$(pwd)":/scan trustsource/ts-deepscan \
  scan -o /scan/results.json /scan

⁠About

Version 2.4.1 · Apache-2.0 Maintained by EACG GmbH · github.com/trustsource/ts-deepscan⁠ · docs⁠

DeepScan is also available as part of the subscription-based TrustSource⁠ platform — the process-focused open source compliance tool covering the full OSS compliance toolchain.

Tag summary

Content type

Image

Digest

sha256:2eecd1cae…

Size

622 MB

Last updated

8 months ago

docker pull trustsource/ts-deepscan