Settings
Open Settings (Ctrl+,, or Cmd+, on macOS) and search for FossID, or edit settings.json directly.
Connection
| Setting | Default | Description |
|---|---|---|
fossid.server.url | (empty) | Address of your FossID server. Set by the sign-in window. Administrators can pre-set it in machine settings, workspace settings or a dev container configuration. |
fossid.remotePolicy.enabled | false | Use your organization's license policy from the FossID policy service instead of the workspace policy file. If the service can't be reached, FossID uses the last fetched copy, then the workspace file. See License policy. |
Automatic scanning
| Setting | Default | Description |
|---|---|---|
fossid.autoScan.enabled | true | Master switch for automatic scanning. When off, only Scan Workspace and Rescan Current File scan. |
fossid.autoScan.onOpen | true | Scan a file when it is opened. |
fossid.autoScan.onSave | true | Scan a file when it is saved. |
fossid.autoScan.onFocus | true | Scan a file when it becomes the active editor. Unchanged files aren't scanned again. |
Scan limits
| Setting | Default | Description |
|---|---|---|
fossid.scan.timeoutSeconds | 1800 | How long Scan Workspace may go without progress before it reports a timeout (60–43200). Each progress update restarts the timer. |
fossid.scan.depResolveTimeoutSeconds | 300 | Time limit for each dependency resolution step (30–1800). Raise it for very large manifests. |
Detection rules
These settings are overridden by the values in .fossid/policy.json once it contains them. See Where the settings are stored.
| Setting | Default | Description |
|---|---|---|
fossid.detectionRules.prohibitedLicense.enabled | true | Report code or license text under a license your policy prohibits. Requires a license policy. |
fossid.detectionRules.conditionalLicense.enabled | true | Report code or license text under a license your policy marks warn, as a warning. Requires a license policy. |
fossid.detectionRules.licenseModifications.enabled | true | Report license texts modified from their standard wording. |
fossid.detectionRules.licenseModifications.thresholdPercent | 5 | How much of a license text (0–100%) must be modified before it is reported. |
fossid.detectionRules.cveInComponent.enabled | true | Report known vulnerabilities of whole matched components (lowest-confidence vulnerability rule). |
fossid.detectionRules.vulnerabilitySnippet.enabled | true | Report snippets matching known-vulnerable upstream code. |
fossid.detectionRules.vulnerableDependency.enabled | true | Report declared dependencies whose resolved version, direct or transitive, has a known vulnerability. |
fossid.detectionRules.vulnerableDependency.includeDevDependencies | false | Also report vulnerabilities in dev dependencies. |
fossid.detectionRules.policyLicenseDependency.enabled | true | Report dependencies under licenses your policy flags (prohibited as error, conditional as warning). Requires a license policy. |
fossid.detectionRules.policyLicenseDependency.includeDevDependencies | false | Also report policy-flagged licenses in dev dependencies. |
Local ports
FossID's two servers listen only on 127.0.0.1. Change these only if the ports clash with something else on your machine. If a port is taken, FossID picks a free one automatically and updates the assistant configuration files. Reload the window after changing them.
| Setting | Default | Description |
|---|---|---|
fossid.port | 39814 | Preferred port of the fossid-editor server (editor actions). |
fossid.mcpPort | 39815 | Preferred port of the fossid-mcp server (the scanner). |