We're not lawyers, but we've read enough licenses to know when your dependencies are about to ruin your week.
A scanner earns trust by being right, and being right the same way every time. Here is the test automation behind OSSScan: 40+ real open-source projects across a dozen ecosystems, a layered pipeline from unit tests to full-app runs, the CLI and the UI diffed against each other, cross-checks against other tools, and deliberate error-condition tests that prove the scanner fails closed instead of guessing.
LicensingA scan comes back with hundreds of Unknown licenses and the temptation is to scroll past. Unknown is not one finding repeated three hundred times: it is seven unrelated situations swept into one bin, some harmless and some a restriction on what you may do with your own product. How to tell them apart, and why the list is worth reading.
LicensingShort answer: yes, to a degree. Permissive does not mean obligation-free. The four kinds of attribution hiding inside your MIT-and-BSD dependency list, what modifying code adds, and how an OSSScan folder scan surfaces every one of them.
ComplianceA formal letter lands in your CEO's inbox referencing dynamic linking and copyright compliance. Who sends it, what you actually owe, how long you have to cure it, and what remediation really looks like, across six delivery models from AGPL SaaS to on-prem GPL to AI-pasted snippets.
Upgrade Strategy“Upgrade right away” is a reflex, not a strategy. Upgrading without one can import a restrictive license, a brand-new exploitable CVE, or a week of unplanned refactoring, while never upgrading sets you up for a code-red fire drill. How to weigh each bump across licensing, security, and technical debt.
IntegrationsOSSScan gives you real insight into your open-source license and CVE risk; Dependabot, free on GitHub, raises the alarm on new CVEs, but as a laundry list, not a verdict. Together they let you treat OSS as a test pass, with managed real-time monitoring in between.
AI & TriageYes, nearly all of them do now. So the real question isn't whether a scanner uses AI, it's whose AI, running where, and who owns the final call. Most bundle their own model and run it in their cloud over your code; OSSScan is a bridge that hands the investigation to the agent you already trust.
Due DiligenceAfter several hundred technical due diligence engagements, one thing has never varied: your open source usage gets examined. Here are the eight questions you will be asked, what a good answer sounds like, and which answers raise a red flag.
Licensing & SecurityOK, even though we are not lawyers, we have watched small dependencies create big licensing surprises and even bigger security headaches. Modern software is built with open source code, and AI is finally giving us clarity about the impact that code brings.
More is on the way on Open Source gotchas, the usual suspects, and getting AI agents to do your triage. But we would rather write what you actually want to read. If there is a topic you want covered, or you have hit a licensing or CVE question that is ruining your week, tell us and we will take a run at it.
Both go straight to Jim at jim@ossscan.com.
No form, no ticket queue, no tracking.