Skip to main content

Settings

Open Settings (Ctrl+,, or Cmd+, on macOS) and search for FossID, or edit settings.json directly.

Connection​

SettingDefaultDescription
fossid.server.url(empty)Address of your FossID server. Set by the sign-in window. Administrators can pre-set it in machine settings, workspace settings or a dev container configuration.
fossid.remotePolicy.enabledfalseUse your organization's license policy from the FossID policy service instead of the workspace policy file. If the service can't be reached, FossID uses the last fetched copy, then the workspace file. See License policy.

Automatic scanning​

SettingDefaultDescription
fossid.autoScan.enabledtrueMaster switch for automatic scanning. When off, only Scan Workspace and Rescan Current File scan.
fossid.autoScan.onOpentrueScan a file when it is opened.
fossid.autoScan.onSavetrueScan a file when it is saved.
fossid.autoScan.onFocustrueScan a file when it becomes the active editor. Unchanged files aren't scanned again.

Scan limits​

SettingDefaultDescription
fossid.scan.timeoutSeconds1800How long Scan Workspace may go without progress before it reports a timeout (60–43200). Each progress update restarts the timer.
fossid.scan.depResolveTimeoutSeconds300Time limit for each dependency resolution step (30–1800). Raise it for very large manifests.

Detection rules​

These settings are overridden by the values in .fossid/policy.json once it contains them. See Where the settings are stored.

SettingDefaultDescription
fossid.detectionRules.prohibitedLicense.enabledtrueReport code or license text under a license your policy prohibits. Requires a license policy.
fossid.detectionRules.conditionalLicense.enabledtrueReport code or license text under a license your policy marks warn, as a warning. Requires a license policy.
fossid.detectionRules.licenseModifications.enabledtrueReport license texts modified from their standard wording.
fossid.detectionRules.licenseModifications.thresholdPercent5How much of a license text (0–100%) must be modified before it is reported.
fossid.detectionRules.cveInComponent.enabledtrueReport known vulnerabilities of whole matched components (lowest-confidence vulnerability rule).
fossid.detectionRules.vulnerabilitySnippet.enabledtrueReport snippets matching known-vulnerable upstream code.
fossid.detectionRules.vulnerableDependency.enabledtrueReport declared dependencies whose resolved version, direct or transitive, has a known vulnerability.
fossid.detectionRules.vulnerableDependency.includeDevDependenciesfalseAlso report vulnerabilities in dev dependencies.
fossid.detectionRules.policyLicenseDependency.enabledtrueReport dependencies under licenses your policy flags (prohibited as error, conditional as warning). Requires a license policy.
fossid.detectionRules.policyLicenseDependency.includeDevDependenciesfalseAlso report policy-flagged licenses in dev dependencies.

Local ports​

FossID's two servers listen only on 127.0.0.1. Change these only if the ports clash with something else on your machine. If a port is taken, FossID picks a free one automatically and updates the assistant configuration files. Reload the window after changing them.

SettingDefaultDescription
fossid.port39814Preferred port of the fossid-editor server (editor actions).
fossid.mcpPort39815Preferred port of the fossid-mcp server (the scanner).