FossID for VS Code
FossID for VS Code brings software composition analysis (SCA) into your editor. As you open and save files, FossID finds open-source code in your workspace and tells you:
- which open-source components your code contains. That includes declared dependencies, vendored libraries, and code that was copied, pasted or AI-generated;
- which licenses apply, and whether your organization's license policy allows them;
- which known vulnerabilities (CVEs) affect the components and dependencies you use.
Findings appear where you already work: in the Problems panel, as squiggles and highlights in the editor, and as short annotations next to each dependency in your manifest files. Every finding can be explained, fixed, or ignored with a recorded reason, right from the editor.
FossID also connects to your AI chat assistant (GitHub Copilot, Claude Code or Cursor). You can ask it to scan, audit and explain your code in plain language, and to generate an SBOM.
What you can do
| Task | Where to read more |
|---|---|
| Install the extension and sign in with your organization account | Getting started, Signing in |
| Get findings automatically as you open and save files, or scan the whole workspace | Scanning |
| Understand what each finding means | Reading findings |
| Ask the AI assistant to explain a finding or propose a fix | Explain and Fix with FossID |
| Decide which licenses are allowed, flagged or prohibited, locally or through your organization's policy service | License policy |
| Turn individual detection rules on or off and tune them | Detection rules |
| Check your code against your organization's own scan servers | Custom scan volumes |
| Accept a finding as an exception, with a reason and an expiry date | Ignoring findings |
| Keep files and folders out of scanning entirely | Excluding files |
| Use FossID from Copilot, Claude Code or Cursor | Using FossID with AI assistants |
| Require compliance review for changes to FossID configuration | Governance |
| Look up a command or setting | Commands, Settings |
| Fix a problem | Troubleshooting |
Requirements
- Visual Studio Code 1.99 or later, or Cursor.
- A FossID subscription. Your organization must be set up for FossID and must have configured sign-in with Microsoft Entra ID or Okta. If you are not yet a FossID customer, run FossID: Request Access from the Command Palette.
- The address of your FossID server. Your administrator can give you this address, or set it for you in advance.
- Optional: an AI chat assistant, to use the conversational features. The supported assistants are GitHub Copilot Chat (Agent Mode), Claude Code (VS Code extension or CLI) and Cursor.
The extension ships with its own scanner for macOS (Apple Silicon and Intel), Linux (x86-64) and Windows (x86-64). You don't need to install anything else.
How it works
When you sign in, the extension starts the FossID scanner in the background on your machine. The scanner talks to your FossID server to identify open-source code. The extension then turns the results into findings in the editor.
The same scanner is also offered to your AI assistant as an MCP server. MCP (Model Context Protocol) is the standard way chat assistants connect to external tools. Your assistant and the editor share one set of scan results. A scan the assistant runs shows up in the editor, and the other way round.
Your sign-in never appears in any file in your workspace. The extension writes only local http://127.0.0.1 addresses into the assistant configuration files.
Note: Scan results are kept in memory for the current window. Reloading or closing the window clears them. They are rebuilt as you open and save files, or when you run FossID: Scan Workspace.