After downloading
- Verify the SHA-256 checksum matches before unzipping (see below).
- Unzip the archive.
- Launch OSSScan and run Compatibility Check from the startup dialog to confirm OSSScan’s required tools are installed on your machine and to generate your machine fingerprint.
- Click Check Project Coverage… in the Compatibility Check dialog to test a project folder, an existing SBOM, or both — no license required — and see whether OSSScan will produce Strong, Partial, or Limited coverage for it before procuring a license.
Verify your download
If you’ve downloaded OSSScan before, your browser may have saved the new file
under a different name (e.g. OSSScan-win32-x64 (1).zip) instead of
overwriting the old one. If your checksum doesn’t match, check your downloads
folder and make sure the command below points at the file you just downloaded,
not an older copy.
Compare the SHA-256 checksum shown on your platform card against the output of:
A matching checksum confirms the file was not corrupted in transit. For stronger authenticity assurance, verify the code signature using the instructions on the Security page. Code signing cannot be forged without our Apple Developer ID or Authenticode certificate, even if this page were compromised.