SOLFIND
Web Lens
Portal home

Licensing Reports — FOSSA Docs

https://docs.fossa.com/docs/reports/licensing-report • 155 KB fetched
Open original page


Licensing Reports — FOSSA Docs Docs Search docs... ⌘K Docs API CLI Glossary Launch App User Guides Product Guides Get Started Project Setup Release Groups Issues Licenses Vulnerabilities Quality SBOM Policies Reports Licensing Reports Remediation Guidance Global Reports Report Settings FOSSA CLI API Reference Integrations fossabot Organization Management On-Premises Deployment Help & Support Legal Get Support fossa.com On this page * Overview * Generating a report from the UI * Choosing a flow * Selecting a format * Selecting report content * Excluding by package label * Saving custom options * Downloading, emailing, or hosting * Generating a report from the CLI * Keeping reports up to date * Modifying dependency data for reports * What's next On this page Docs Reports Licensing Reports Licensing Reports Generate, customize, and publish licensing reports and bills of materials from FOSSA. 5 min read Updated Aug 26, 2026 Copy link Overview Open source licenses require you to give attribution to their authors in specific ways. FOSSA generates the compliance documentation automatically (licensing reports, copyright disclosures, and bills of materials) based on the dependencies it has analyzed. Licensing reports are useful for: * Distributing attribution notices with your product * Customer-facing bills of materials for sales, partnerships, or OEMs * Audit reports for due diligence events * Security vulnerability reviews Generating a report from the UI Navigate to a project or release group , open Reports , and select Licensing from the sidebar. Generating a report takes two steps: choose a flow, then select an output format and adjust the content options. A live preview updates as you change options. Expand Note All FOSSA plans can generate Standard reports using pre-set filters. The Custom report flow (which lets you control every filter, view, and data point) requires a paid plan. Choosing a flow Flow Description Standard (Recommended) Pre-set options, consistent, quick, available to all plans Custom Full control over included content and data points, paid plans only The Standard flow includes a fixed set chosen by FOSSA: Dependencies Summary, Direct Dependencies, Notice File(s), Package Metadata, and Concluded License(s) when license conclusions are enabled for your organization . Selecting a format FOSSA supports five output formats for licensing reports: Format Best for HTML Hosting on your website or a public page PDF Distributing as a document to customers or auditors CSV Spreadsheet-based review or processing Markdown Embedding in source code or documentation Plain Text Simple distribution or embedding in built artifacts Expand Selecting report content The following options control what appears in the generated report: Option Description Dependencies Summary An overview of all dependencies and licenses found. Direct Dependencies First-level dependencies explicitly included in your project. Transitive Dependencies Indirect dependencies pulled in by your direct dependencies. Snippet Dependencies Dependencies detected via code snippets . Available when snippet detection is enabled for your organization. Hash and Version Data Includes package hashes and version identifiers for each dependency . Package Labels Includes any package labels assigned to packages in your organization. List of Licenses Includes license information for each dependency. Choose which license data to include: Declared Licenses, First Party Licenses, Copyrights from non-license text. Exclude Package Labels Excludes packages that have certain labels, such as Dynamically Linked, Modified, Statically Linked, or Unmodified. Concluded License(s) Any licenses that have been manually concluded on a dependency. Only available when the License Conclusion feature is enabled for your organization. Notice File(s) Verbatim text from NOTICE.TXT , THIRD-PARTY-NOTICES.TXT , and similar files. Dependency Metadata Per-dependency details. Choose which fields to include: Project, Authors, Description, Concluded License, Declared License , License Header, Full License Text, Discovered License (s), File Path, Package Manager, Package Homepage, Package Download URL, Dependency Paths, Issue Resolution Notes, Copyrights, License URL. Excluding by package label In Custom mode, the Exclude Package Labels filter lets you omit dependencies that carry specific package labels from the report output, useful for excluding test-only or internal dependencies that shouldn't appear in customer-facing attribution. Saving custom options In the Custom flow, save a configuration you use often as a named preset from the Saved Options control, then apply it to future reports in one click. See Report Settings for managing presets and choosing a default. Saved options require a paid plan. Downloading, emailing, or hosting Once generated, you can: * Download the report to your computer immediately * Email the report, for large projects, click Email to queue generation as a background job; the completed report is delivered to your email address * Host the report via FOSSA, FOSSA generates a persistent public URL that always serves the latest version, updating automatically with each new scan Generating a report from the CLI The FOSSA CLI can generate licensing reports directly, which is useful for automating report generation in CI. Shell Copy export FOSSA_API_KEY=XXXXXXXX fossa analyze && fossa report attribution --format spdx Note The CLI supports additional formats beyond the web UI: csv , cyclonedx-json , cyclonedx-xml , html , json , markdown , spdx , spdx-json , and text . See fossa report for the full reference. Keeping reports up to date Attribution notices become stale as dependencies change. To keep them current: * Integrate FOSSA into your CI pipeline so a fresh report is available at every commit * Use the FOSSA API to fetch the latest file as part of your release process * If using hosted reports, FOSSA updates them automatically Modifying dependency data for reports If a dependency appears in your report with incorrect or missing information (wrong license, missing author, no copyright text) you can correct it directly in FOSSA before regenerating. See License Corrections for the full workflow, including how to: * Conclude or change a detected license * Update author and description metadata * Add or edit copyright text * Remove a dependency from the report entirely What's next * Generating SBOMs : Export your project's full bill of materials in SPDX or CycloneDX format. * Licensing Policies : Configure which licenses are approved, flagged, or denied to improve future report outcomes. * Reviewing Licensing Issues : Resolve open licensing issues before regenerating your report. Previous Global Reports Next Remediation Guidance © 2026 FOSSA, Inc. [email protected]

Links found on this page

  1. Docs [direct]
  2. Docs [direct]
  3. API [direct]
  4. CLI [direct]
  5. Glossary [direct]
  6. Launch App [direct]
  7. User Guides [direct]
  8. Product Guides [direct]
  9. Project Setup [direct]
  10. Release Groups [direct]
  11. Issues [direct]
  12. Licenses [direct]
  13. Vulnerabilities [direct]
  14. Quality [direct]
  15. SBOM [direct]
  16. Policies [direct]
  17. Reports [direct]
  18. Licensing Reports [direct]
  19. Remediation Guidance [direct]
  20. Global Reports [direct]
  21. Report Settings [direct]
  22. Integrations [direct]
  23. fossabot [direct]
  24. Organization Management [direct]
  25. On-Premises Deployment [direct]
  26. Help & Support [direct]
  27. Legal [direct]
  28. Get Support [direct]
  29. fossa.com [direct]
  30. Security vulnerability reviews [direct]
  31. code snippets [direct]
  32. package labels [direct]
  33. fossa report [direct]
  34. License Corrections [direct]
  35. Generating SBOMs [direct]
  36. Licensing Policies [direct]
  37. Reviewing Licensing Issues [direct]