Skip to content
@aboutcode-org

AboutCode

Bring together best-in-class open source Software Composition Analysis (SCA) tools and data for open compliance and software supply chain security.

Pinned Loading

  1. scancode-toolkit scancode-toolkit Public

    🔍 ScanCode detects licenses, copyrights, dependencies by "scanning code" ... to discover and inventory open source and third-party packages used in your code. Sponsored by NLnet, the Google Summer …

    Python 2.4k 658

  2. vulnerablecode vulnerablecode Public

    A free and open vulnerabilities database and the packages they impact. And the tools to aggregate and correlate these vulnerabilities. Sponsored by NLnet https://nlnet.nl/project/vulnerabilitydatab…

    Python 641 262

  3. scancode.io scancode.io Public

    ScanCode.io is a server to script and automate software composition analysis pipelines with ScanPipe pipelines. This project is sponsored by NLnet project https://nlnet.nl/project/vulnerabilitydata…

    Python 166 152

  4. purldb purldb Public

    Tools to create and expose a database of purls (Package URLs). This project is sponsored by NLnet project https://nlnet.nl/project/vulnerabilitydatabase/ and nexB for https://www.aboutcode.org/ Cha…

    HTML 58 44

  5. dejacode dejacode Public

    Automate open source license compliance and ensure software supply chain integrity

    Python 37 18

  6. scancode-action scancode-action Public

    Run ScanCode.io pipelines from your Workflows

    12 3

Repositories

Showing 10 of 142 repositories
  • aboutcode-mirror-nuget-catalog Public

    Append-only mirror of NuGet Catalog, updated hourly

    aboutcode-org/aboutcode-mirror-nuget-catalog’s past year of commit activity
    Python 1 3 0 0 Updated Jan 8, 2026
  • scancode-licensedb Public

    A free and open database of all the licenses, in particular all the open source software licenses

    aboutcode-org/scancode-licensedb’s past year of commit activity
    Makefile 55 10 21 (10 issues need help) 3 Updated Jan 8, 2026
  • purldb Public

    Tools to create and expose a database of purls (Package URLs). This project is sponsored by NLnet project https://nlnet.nl/project/vulnerabilitydatabase/ and nexB for https://www.aboutcode.org/ Chat is at https://gitter.im/aboutcode-org/discuss

    aboutcode-org/purldb’s past year of commit activity
    HTML 58 43 287 (1 issue needs help) 8 Updated Jan 8, 2026
  • scancode-toolkit Public

    🔍 ScanCode detects licenses, copyrights, dependencies by "scanning code" ... to discover and inventory open source and third-party packages used in your code. Sponsored by NLnet, the Google Summer of Code, Azure credits, nexB and other generous sponsors!

    aboutcode-org/scancode-toolkit’s past year of commit activity
    Python 2,449 657 1,170 (4 issues need help) 92 Updated Jan 8, 2026
  • typecode Public

    TypeCode provides comprehensive filetype and mimetype detection using multiple detectors including libmagic (included as a dependency for Linux, Windows and macOS) and Pygments.

    aboutcode-org/typecode’s past year of commit activity
    Python 9 11 14 2 Updated Jan 8, 2026
  • commoncode Public

    A library of common functions shared in many other AboutCode projects

    aboutcode-org/commoncode’s past year of commit activity
    Python 4 21 11 (1 issue needs help) 1 Updated Jan 8, 2026
  • aboutcode-toolkit Public

    ✅ AboutCode Toolkit provides a simple way to document provenance metadata (origin and license) about third-party code that you use in your project: it includes utilities to generate inventory/BOM or Attribution documentation.

    aboutcode-org/aboutcode-toolkit’s past year of commit activity
    Python 98 49 6 11 Updated Jan 8, 2026
  • purlvalidator-go Public

    Offline Package URL validator using a prebuilt FST of known packages.

    aboutcode-org/purlvalidator-go’s past year of commit activity
    Go 0 Apache-2.0 0 0 0 Updated Jan 8, 2026
  • purl-validator.rs Public

    Offline Package URL validator using a prebuilt FST of known packages.

    aboutcode-org/purl-validator.rs’s past year of commit activity
    Rust 0 Apache-2.0 0 0 0 Updated Jan 8, 2026
  • aboutcode-mirror-kev Public

    AboutCode Mirror for CISA Known Exploited Vulnerabilities

    aboutcode-org/aboutcode-mirror-kev’s past year of commit activity
    1 4 0 0 Updated Jan 8, 2026