Skip to main content

Scanning

FossID scans in two ways:

  • Automatically, one file at a time, as you open, switch to and save files. This is on by default.
  • On demand, for the whole workspace, with FossID: Scan Workspace.

Automatic scanning​

A file is scanned when you:

  • open it;
  • switch to it, i.e. it becomes the active editor tab. This also covers files that were already open when the editor started;
  • save it.

Opening and switching are cheap. If a file hasn't changed on disk since FossID last scanned it in this window, the earlier results are shown and no new scan runs. Saving always re-scans.

Several quick events on the same file are combined into one scan.

What a scan looks for​

Source files are checked for:

  • code that matches known open-source components, whole files or snippets;
  • license texts in the file itself, and whether they have been modified from the standard wording;
  • code snippets that match known-vulnerable upstream code.

Dependency manifests are resolved instead. FossID works out the version of every declared dependency and its transitive dependencies (up to five levels deep), then checks them for known vulnerabilities and for licenses your policy flags. The supported manifests are:

FileEcosystemDependency sections read
package.jsonnpmdependencies, devDependencies, optionalDependencies, peerDependencies
Cargo.tomlRust / Cargo[dependencies], [dev-dependencies], [build-dependencies], [target.*.dependencies]
pom.xmlMaven<dependency> entries
go.modGorequire entries, including // indirect
*.csprojNuGet<PackageReference> entries
requirements.txtpiprequirement lines
pyproject.tomlPEP 621 / Poetrydependencies and [tool.poetry.dependencies]
PipfilePipenv[packages], [dev-packages] and named categories

File names must match exactly. Variants such as dev-requirements.txt are scanned as ordinary files, not as manifests.

Files that are never scanned automatically​

  • Files outside your workspace folders, and editors that aren't files on disk (diff views, output panels and similar).
  • Files larger than 10 MB.
  • FossID's own configuration: anything in a .fossid/ folder, plus .fossidignore, .fossidpolicy and fossidpolicy.
  • Editor and tool folders: .vscode/, .cursor/, .git/, and the file .mcp.json.
  • Anything you have excluded with .fossidignore (see Excluding files).

Turning automatic scanning off​

SettingDefaultEffect
fossid.autoScan.enabledonMaster switch. When off, nothing is scanned automatically; Scan Workspace and Rescan Current File still work.
fossid.autoScan.onOpenonScan when a file is opened.
fossid.autoScan.onFocusonScan when a file becomes the active editor.
fossid.autoScan.onSaveonScan when a file is saved.

The auto-scan status bar item​

A FossID item in the status bar shows the state of the current file:

TextMeaning
FossID (shield icon)Idle.
FossID scanning…A scan of this file is running.
FossID: cleanThe last scan found nothing.
FossID: N finding(s)The last scan found N findings.
FossID: scan failedThe last scan couldn't finish. See Troubleshooting.

Clicking it runs FossID: Rescan Current File.

Rescan Current File​

FossID: Rescan Current File scans the active file right away, ignoring any cached result.

  • If the file has unsaved changes, FossID saves it first.
  • If the file is excluded by .fossidignore, FossID scans it anyway and tells you so: <path> matches .fossidignore — scanning anyway; auto-scan skips this file. Use this to check an excluded file without removing the exclusion.

Scan Workspace​

FossID: Scan Workspace scans the whole workspace in one go: every source file, plus every dependency manifest. Run it from the Command Palette, or from the … menu of the Policies view in the FossID side bar.

A progress notification walks through the steps: connecting, loading the policy, scanning the project, resolving dependency manifests, enriching components, and publishing findings. The main FossID status bar item shows FossID: Scanning while it runs.

Things to know:

  • It replaces all current results. Scan Workspace starts from a clean slate, including results your AI assistant produced in this window.
  • Only the first folder is scanned in a multi-root workspace.
  • It can't be cancelled once started. The setting fossid.scan.timeoutSeconds (default 1800 seconds, i.e. 30 minutes) limits how long it may go without making progress. The timer restarts every time the scan reports progress.
  • Dependency resolution on large manifests can take a minute or more. The setting fossid.scan.depResolveTimeoutSeconds (default 300 seconds) limits each resolution step.

When the scan finishes, FossID offers Analyze Findings. This opens your AI chat with a prompt asking the assistant to audit the results, without scanning again. See Using FossID with AI assistants.

Scan Workspace Against Volume…​

If your organization has configured custom scan volumes, FossID: Scan Workspace Against Volume… checks the workspace against one of them. Unlike Scan Workspace, it adds to your current results instead of replacing them.

When results change without a new scan​

You don't always need a new scan to see updated findings. FossID re-evaluates the existing results immediately when you:

  • change the license policy or the detection rules;
  • add, change or remove an ignore;
  • change .fossidignore. Findings for newly excluded files disappear right away.

While you edit​

As soon as you start typing in a file, FossID removes that file's findings, and in a manifest its dependency annotations. They would otherwise point at the wrong lines. Save the file, and FossID scans it again and shows fresh results.