Skip to main content

Explain and Fix with FossID

Every FossID finding has two actions that hand it to your AI chat assistant, with all the context it needs:

  • Explain with FossID: what was found, why your policy flagged it, what it obliges you to do, and your options.
  • Fix with FossID: one concrete, defensible fix, which the assistant proposes or applies.

These actions need an AI chat in your editor: Copilot Chat in VS Code, or Cursor's chat.

Where to find them​

  • Quick Fix. Put the cursor on a FossID squiggle and press Ctrl+. (Cmd+. on macOS), or click the lightbulb. The actions are also in the right-click menu of a finding in the Problems panel.
  • Hover over a FossID squiggle. Each finding has Explain with FossID and Fix with FossID links.
  • Right-click in the editor while the cursor is on a finding: FossID: Explain Finding and FossID: Fix Finding.

If several findings overlap at the cursor, FossID asks Several FossID findings here — which one?. Type to filter the list by message.

What happens​

FossID opens your editor's AI chat with a short, structured prompt:

/fossid-explain

- Finding: license GPL-3.0-only
- File: src/vendor/parser.c, line 42
- Message: Prohibited license: GPL-3.0-only (inherited from …)
- Source: https://github.com/…
- Also: …
  • VS Code: the prompt is sent to Copilot Chat right away.
  • Cursor: the prompt is placed in the chat box. Press Enter to send it.

If the chat can't be opened, FossID copies the prompt to your clipboard so you can paste it yourself.

Claude Code​

The actions open the editor's built-in chat, not Claude Code. In Claude Code, type the same commands yourself: /fossid-explain or /fossid-fix, followed by the finding. The extension installs both skills for Claude Code automatically.

What the assistant does​

The assistant follows FossID's bundled fossid-explain and fossid-fix skills. It reads your license policy and existing ignores, and uses the current scan results. It never starts a new scan.

Explain answers in a few short sections:

  • What was found
  • Why it was flagged
  • Your options, ranked, ending with the option to record a documented exception
  • To confirm: what to check before acting

It takes into account how your project is delivered, for example a product you distribute or a service you host. License obligations differ between the two.

Fix picks the most appropriate change, in this order of preference:

  1. Replace the code (always first for prohibited copied code).
  2. Upgrade or swap the dependency.
  3. Isolate it architecturally.
  4. Meet the license obligation, for example restore a missing license text.
  5. Record an exception. For vulnerabilities this is a VEX-style statement explaining why you are not affected.
  6. Obtain a license that permits your use.

The assistant makes a change itself when it can carry it out and check it, such as rewriting a snippet or bumping a version. It stops and asks when the decision is yours, such as recording an exception.

It answers under Proposed change, Why this one, Before you apply and If that is not workable.

Note: Both skills end with a reminder that their output is not legal advice. For license decisions with legal consequences, involve your compliance team.