Skip to main content

License policy

Your license policy tells FossID how to treat each license it finds:

ActionEffect
AllowNo finding.
WarnA conditional license warning: allowed, but check the conditions.
ErrorA prohibited license error: must not be used.

You can set an action for a single license (by its SPDX identifier, such as GPL-3.0-only) or for a whole category:

CategoryExamples
PermissiveMIT, Apache-2.0, BSD
Weak CopyleftLGPL, MPL
Strong CopyleftGPL, AGPL
Source AvailableBUSL, Elastic
Source Available (Non-Commercial)licenses that forbid commercial use
Commercialproprietary licenses
Non Licensetexts that aren't licenses
Uncategorizedlicenses FossID hasn't categorized

The license rules (prohibited license, conditional license and license policy in dependencies) only fire when a policy is in force. Without one, FossID still reports vulnerabilities and modified license texts.

There are two ways to provide a policy:

  • A workspace policy file, .fossid/policy.json, committed with your code. You edit it in the License Policies editor.
  • Your organization's policy service. One central policy for every project, managed by your compliance team. See Using your organization's policy service.

The License Policies editor​

Open the FossID side bar and select License Policies in the Policies view.

Add a rule:

  1. Choose Type: License or Category.
  2. Pick the Identifier from the list. Type to filter. Only licenses FossID knows are accepted, so there are no typos. Items already in your policy aren't listed.
  3. Choose the Action: Allow, Warn or Error.
  4. Select Add.

Adding a license or category that is already in the policy updates its action.

Manage rules:

  • The table lists every rule with its Type, Identifier, Category and Action.
  • Use the Filter box to search by type, identifier, category or action. Matching ignores case, spaces and hyphens, so gpl 3 finds GPL-3.0-only.
  • Change a rule's Action with its drop-down.
  • Select Remove to delete a rule. This takes effect immediately, without asking for confirmation.
  • Select the eye icon on a license row to see the license's details: full name, whether it is OSI-approved, category, reference links and full text.

Changes are saved automatically to .fossid/policy.json in your workspace folder and take effect immediately. Findings are re-evaluated without rescanning.

Note: The license list comes from the running FossID scanner. Until the scanner is ready, the editor shows Loading SPDX list… and the Add button is disabled.

The policy file​

The policy lives in .fossid/policy.json at the root of your first workspace folder. The same file also holds your detection rule settings and custom volumes.

{
"version": 1,
"policy": [
{ "id": "GPL-3.0-only", "type": "license", "action": "error", "reason": "Not allowed in shipped products" },
{ "id": "StrongCopyleft", "type": "category", "action": "error", "reason": "" },
{ "id": "WeakCopyleft", "type": "category", "action": "warn", "reason": "Check linking" },
{ "id": "MIT", "type": "license", "action": "allow", "reason": "" }
]
}
FieldMeaning
idAn SPDX license identifier, or a category name (Permissive, WeakCopyleft, StrongCopyleft, SourceAvailable, SourceAvailableNc, Commercial, NonLicense, Uncategorized).
typelicense or category.
actionallow, warn or error.
reasonOptional explanation, shown in the finding's message.

You can edit the file by hand, switch branches, or pull changes. FossID notices and re-evaluates findings immediately.

  • Older formats. FossID also reads a policy from .fossidpolicy or fossidpolicy at the workspace root, if there is no .fossid/policy.json. The editor always saves to .fossid/policy.json, which then takes precedence.
  • Invalid JSON. If the file isn't valid JSON, FossID treats the policy as empty and reports no license findings. The next save from the editor overwrites the file.

We recommend committing .fossid/policy.json so the whole team works to the same policy. Use Governance to require compliance review for changes to it.

Using your organization's policy service​

Instead of a policy per workspace, your organization can keep one central policy in the FossID policy service. Every developer and every project then uses the same rules, and your compliance team changes them in one place.

Turning it on​

Turn on the setting fossid.remotePolicy.enabled. In the Settings UI, search for FossID remote policy. It is off by default.

FossID restarts its scanner to switch over. Findings are rebuilt as files are scanned again. Your AI assistant may need to reconnect.

Where the policy comes from​

With the policy service on, FossID uses the first policy it can get:

  1. The policy service. This is the normal case.
  2. The last copy fetched on this machine, if the service can't be reached.
  3. The workspace policy file (.fossid/policy.json), if no copy has been fetched yet.

Hover over the FossID status bar item to see which policy is in force:

Tooltip lineMeaning
Policy: FossID policy serviceThe central policy is in force.
Policy: last fetched copy — the policy service is unreachableThe service couldn't be reached. FossID is using the copy it fetched last time.
Policy: workspace policy file — the policy service is unavailableThe service couldn't be reached and no copy was available, so FossID is using the workspace file.
Policy: the remote policy could not be loadedNo policy could be loaded at all. License findings are not reported.

When FossID has to fall back, it also tells you once with a warning, for example FossID: <reason> — using the last fetched policy. It doesn't repeat the warning until the service has worked again.

Note: With the policy service on, the License Policies editor still edits the workspace file. That file is only used as a fallback, or when you publish it (below). Detection rule settings and custom volumes always come from the workspace file.

Publishing a policy to the service​

Compliance owners can upload a workspace policy to the service with FossID: Publish Policy:

  1. Prepare the policy in the License Policies editor (or in .fossid/policy.json).
  2. Run FossID: Publish Policy from the Command Palette.
  3. Confirm: Publish <file> to the FossID policy service as "default"? — This replaces the policy that every scan using the policy service resolves to. Select Publish.

A notification confirms when the policy is published. If the policy service is on in your window, FossID starts using the new policy right away.

Publishing needs an account with write access to the policy service. If you don't have it, the error from the service is shown; ask your FossID administrator.

If someone else changed the policy in the meantime, FossID refuses to overwrite it silently and offers Refresh & Retry. It then asks: The policy on the FossID policy service changed since it was last fetched. Overwrite it with your local policy? Select Overwrite only if you're sure your version should replace theirs.