OSSScan Blog

We're not lawyers, but we've read enough licenses to know when your dependencies are about to ruin your week.

How We Test OSSScan: 40+ Real Projects, Every Layer, Every Run

A scanner earns trust by being right, and being right the same way every time. Here is the test automation behind OSSScan: 40+ real open-source projects across a dozen ecosystems, a layered pipeline from unit tests to full-app runs, the CLI and the UI diffed against each other, cross-checks against other tools, and deliberate error-condition tests that prove the scanner fails closed instead of guessing.

Unknown Licenses in Open Source Scanning: Why They Happen and Why Ignoring Them Is a Mistake

A scan comes back with hundreds of Unknown licenses and the temptation is to scroll past. Unknown is not one finding repeated three hundred times: it is seven unrelated situations swept into one bin, some harmless and some a restriction on what you may do with your own product. How to tell them apart, and why the list is worth reading.

Do I Need to Care About Permissive Licenses?

Short answer: yes, to a degree. Permissive does not mean obligation-free. The four kinds of attribution hiding inside your MIT-and-BSD dependency list, what modifying code adds, and how an OSSScan folder scan surfaces every one of them.

“We Shipped Copyleft”: What Happens After an Open Source License Breach?

A formal letter lands in your CEO's inbox referencing dynamic linking and copyright compliance. Who sends it, what you actually owe, how long you have to cure it, and what remediation really looks like, across six delivery models from AGPL SaaS to on-prem GPL to AI-pasted snippets.

Should You Always Install the Latest Versions of Your Open Source Packages?

“Upgrade right away” is a reflex, not a strategy. Upgrading without one can import a restrictive license, a brand-new exploitable CVE, or a week of unplanned refactoring, while never upgrading sets you up for a code-red fire drill. How to weigh each bump across licensing, security, and technical debt.

Dependabot and OSSScan: Better Together

OSSScan gives you real insight into your open-source license and CVE risk; Dependabot, free on GitHub, raises the alarm on new CVEs, but as a laundry list, not a verdict. Together they let you treat OSS as a test pass, with managed real-time monitoring in between.

Don't Other Open Source Scanners Use AI Too?

Yes, nearly all of them do now. So the real question isn't whether a scanner uses AI, it's whose AI, running where, and who owns the final call. Most bundle their own model and run it in their cloud over your code; OSSScan is a bridge that hands the investigation to the agent you already trust.

The Eight Open Source Questions Every Technical Due Diligence Asks

After several hundred technical due diligence engagements, one thing has never varied: your open source usage gets examined. Here are the eight questions you will be asked, what a good answer sounds like, and which answers raise a red flag.

Why Open Source Software (OSS) Matters

OK, even though we are not lawyers, we have watched small dependencies create big licensing surprises and even bigger security headaches. Modern software is built with open source code, and AI is finally giving us clarity about the impact that code brings.

What should we write about next?

More is on the way on Open Source gotchas, the usual suspects, and getting AI agents to do your triage. But we would rather write what you actually want to read. If there is a topic you want covered, or you have hit a licensing or CVE question that is ruining your week, tell us and we will take a run at it.

Both go straight to Jim at jim@ossscan.com.
No form, no ticket queue, no tracking.