DejaCode provides an enterprise-level application to automate open source license compliance and ensure software supply chain integrity, powered by ScanCode, the industry-leading code scanner.
DejaCode is your system of record as a single source of truth with quality data for licenses, vulnerabilities, and package provenance and metadata, enabling you to ensure FOSS compliance with enterprise-grade features and integrations for DevOps and software systems.
Instructions to get you up and running on your local machine are at Getting Started
The DejaCode documentation also provides:
- prerequisites for installing the software.
- instructions for configuring DejaCode integration with ScanCode.io, VulnerableCode, and PurlDB.
- tutorials that provide hands-on guidance to DejaCode features.
- how to setup usage policies.
- how to capture and share software inventories (SBOMs) in multiple file formats and standards, such as CycloneDX and SPDX.
- how to customize your own workflows and reports.
- guidelines for contributing to code development.
Thank you for your interest in contributing to AboutCode projects. Please read the following guidelines carefully before getting started.
| Tests | Documentation |
|---|---|
DejaCode is an enterprise-level application to automate open source license compliance and ensure software supply chain integrity, powered by ScanCode, the industry-leading code scanner.
SPDX-License-Identifier: AGPL-3.0-only
Copyright (c) nexB Inc., AboutCode and others
This program is free software: you can redistribute it and/or modify it under the terms of the GNU Affero General Public License as published by the Free Software Foundation, version 3 of the License.
This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU Affero General Public License for more details.
You should have received a copy of the GNU Affero General Public License along with this program. If not, see <https://www.gnu.org/licenses/>.
nexB offers a commercial services option for DejaCode. You can learn more about these options by contacting nexB at https://www.nexb.com/contact-us/
This project is funded, supported and sponsored by:
- Generous support and contributions from users like you!
- the European Commission NGI programme
- the NLnet Foundation
- the Swiss State Secretariat for Education, Research and Innovation (SERI)
- Google, including the Google Summer of Code and the Google Seasons of Doc programmes
- Mercedes-Benz Group
- Microsoft and Microsoft Azure
- AboutCode ASBL
- nexB Inc.
This project was funded through the NGI0 Entrust Fund, a fund established by NLnet with financial support from the European Commission's Next Generation Internet programme, under the aegis of DG Communications Networks, Content and Technology under grant agreement No 101069594.
https://nlnet.nl/project/CRAVEX/


