Skip to main content

FossID for VS Code

FossID for VS Code brings software composition analysis (SCA) into your editor. As you open and save files, FossID finds open-source code in your workspace and tells you:

  • which open-source components your code contains. That includes declared dependencies, vendored libraries, and code that was copied, pasted or AI-generated;
  • which licenses apply, and whether your organization's license policy allows them;
  • which known vulnerabilities (CVEs) affect the components and dependencies you use.

Findings appear where you already work: in the Problems panel, as squiggles and highlights in the editor, and as short annotations next to each dependency in your manifest files. Every finding can be explained, fixed, or ignored with a recorded reason, right from the editor.

FossID also connects to your AI chat assistant (GitHub Copilot, Claude Code or Cursor). You can ask it to scan, audit and explain your code in plain language, and to generate an SBOM.

What you can do​

TaskWhere to read more
Install the extension and sign in with your organization accountGetting started, Signing in
Get findings automatically as you open and save files, or scan the whole workspaceScanning
Understand what each finding meansReading findings
Ask the AI assistant to explain a finding or propose a fixExplain and Fix with FossID
Decide which licenses are allowed, flagged or prohibited, locally or through your organization's policy serviceLicense policy
Turn individual detection rules on or off and tune themDetection rules
Check your code against your organization's own scan serversCustom scan volumes
Accept a finding as an exception, with a reason and an expiry dateIgnoring findings
Keep files and folders out of scanning entirelyExcluding files
Use FossID from Copilot, Claude Code or CursorUsing FossID with AI assistants
Require compliance review for changes to FossID configurationGovernance
Look up a command or settingCommands, Settings
Fix a problemTroubleshooting

Requirements​

  • Visual Studio Code 1.99 or later, or Cursor.
  • A FossID subscription. Your organization must be set up for FossID and must have configured sign-in with Microsoft Entra ID or Okta. If you are not yet a FossID customer, run FossID: Request Access from the Command Palette.
  • The address of your FossID server. Your administrator can give you this address, or set it for you in advance.
  • Optional: an AI chat assistant, to use the conversational features. The supported assistants are GitHub Copilot Chat (Agent Mode), Claude Code (VS Code extension or CLI) and Cursor.

The extension ships with its own scanner for macOS (Apple Silicon and Intel), Linux (x86-64) and Windows (x86-64). You don't need to install anything else.

How it works​

When you sign in, the extension starts the FossID scanner in the background on your machine. The scanner talks to your FossID server to identify open-source code. The extension then turns the results into findings in the editor.

The same scanner is also offered to your AI assistant as an MCP server. MCP (Model Context Protocol) is the standard way chat assistants connect to external tools. Your assistant and the editor share one set of scan results. A scan the assistant runs shows up in the editor, and the other way round.

Your sign-in never appears in any file in your workspace. The extension writes only local http://127.0.0.1 addresses into the assistant configuration files.

Note: Scan results are kept in memory for the current window. Reloading or closing the window clears them. They are rebuilt as you open and save files, or when you run FossID: Scan Workspace.