Custom scan volumes
A custom scan volume is an extra FossID scan server that your organization hosts. It typically holds code FossID's own knowledge base doesn't know about: your company's other products, a customer's codebase, or code you have licensed under specific terms.
When volumes are configured, FossID checks your files against each of them in addition to your main FossID server. A match on a volume is reported as its own finding. It doesn't mean there is a license problem. It means this code also appears in someone else's codebase, which only you can judge.
Adding a volume
- Open Detection Rules, from the FossID side bar (Policies view) or with FossID: Open Detection Rules.
- In the Custom Volumes section, enter a Name and the volume's URL (for example
https://scan.corp.example). - Select Add volume.
New volumes start at severity Error. Change it in the volume's row:
| Severity | Use it when a match on this volume is… |
|---|---|
| Error | a serious problem that must be fixed. |
| Warning | worth reviewing. |
| Info | routine, but good to know. |
To remove a volume, select Remove and confirm. Its findings stop appearing.
Naming rules:
- up to 64 letters, digits, dots, dashes and underscores, starting with a letter or digit;
- unique (ignoring case);
- the name
fossidis reserved for your main server.
URL rules: must start with https:// (or http:// for a local server). Don't include a username or password in the URL.
Volumes are stored in .fossid/policy.json and committed with your code. The file must never contain credentials. A folder must be open to configure volumes.
{
"volumes": [
{ "name": "corp-products", "url": "https://scan.corp.example", "severity": "error" },
{ "name": "partner-x", "url": "https://scan.partner.example", "severity": "warn" }
]
}
In the file, severity is error, warn or info.
When volumes are scanned
- On save. After FossID scans a saved file against your main server, it scans the file against each volume in turn. If a volume can't be reached, that pass is skipped (details go to the FossID output channel) and your other results are unaffected.
- On demand. FossID: Scan Workspace Against Volume… checks the whole workspace against one volume. If you have several, pick one from the list. Results are added to your current findings, tagged with the volume. If no volumes are configured, FossID offers Add a Volume.
What a volume match looks like
- In the Problems panel, under the source FossID ·
<volume name>, with the codefossid/custom-volume-match. For example:Matches <component> <version> as <path> in custom volume "corp-products" (score 97).A partial match starts with Partially matches. - Severity: a whole-file match uses the volume's severity. A partial (snippet) match is one step lower: Error becomes Warning, Warning becomes Info.
- A whole-file match is shown as a coloured band across the first line of the file, with the text ⚠ Whole-file match ·
<volume>, or · N volumes if several volumes match. Hover over it for details. - A snippet match is underlined in the editor, like other findings.
A volume match is not a license question, so your license policy doesn't change it. License findings for the same code are still reported separately.
Ignoring a volume match
Volume matches can be ignored like other findings, with a reason and an expiry:
- A whole-file match is ignored by component, with a
componententry:path:component:<name>@<version>. Use<name>@*to cover all versions. - A snippet match is ignored by its snippet ID.