TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Show HN: Fossa-cli – Fast and reliable dependency analysis for any codebase

104 pointsby XiZhaoabout 7 years ago

10 comments

andmariosabout 7 years ago
This looks great, alas I am unable to test it.<p>When I try to sign up, they want write access to my repos, to the org repos I am a member off, etc. Let&#x27;s make this clear: I am not giving to anyone write access to my repos and certainly not to other people repos. Read permissions should be enough. You want to add something to my repo? Do a PR.<p>So what remains, is to test the command line app without using the online service. But the documentation is bad, so I am not able to do that either. No docs for scala, when trying with go, I get cryptic errors, like &#x27;no supported Go build tools detected&#x27; until I install a third party go binary (godep or govendor) and &#x27;could not find Go project folder (maybe your Go build tool is not supported?)&#x27;.<p>The idea is great, the execution needs some work.
评论 #16595024 未加载
评论 #16602711 未加载
评论 #16595410 未加载
achouabout 7 years ago
I like that FOSSA scans FOSSA. Here&#x27;s the link from the &quot;license scan&quot; badge on github: <a href="https:&#x2F;&#x2F;app.fossa.io&#x2F;projects&#x2F;git%2Bgithub.com%2Ffossas%2Ffossa-cli&#x2F;refs&#x2F;branch&#x2F;master&#x2F;abc139975f7d6e9d8b43648782065bec02a9ffd3" rel="nofollow">https:&#x2F;&#x2F;app.fossa.io&#x2F;projects&#x2F;git%2Bgithub.com%2Ffossas%2Ffo...</a>
评论 #16595449 未加载
评论 #16595772 未加载
mypitchabout 7 years ago
Impressive work. It takes courage to tackle the over-complicated compliance area - a headache to a lot of startup owners including myself. Thanks for simplifying the annoying compliance verification &amp; maintenance processes and make it accessible to everyone.
ibdfabout 7 years ago
Fun fact, in Portuguese Fossa means cesspool but hopefully this was named after the animal ;)
评论 #16595368 未加载
helbabout 7 years ago
Nice looking website! I believe i&#x27;ve encountered some broken links:<p>- the <i>&quot;Upload Build Scan&quot;</i> button links to Readme on Github, is it intentional?<p>- GitLab logo (under &quot;<i>WORKFLOW TOOLS</i>&quot;) links to Bitbucket&#x2F;Stash docs instead of <a href="https:&#x2F;&#x2F;fossa.io&#x2F;docs&#x2F;integrating-tools&#x2F;gitlab&#x2F;" rel="nofollow">https:&#x2F;&#x2F;fossa.io&#x2F;docs&#x2F;integrating-tools&#x2F;gitlab&#x2F;</a><p>And the constantly changing window title (&quot;<i>Kevin says…</i>&quot;) makes me want to close the tab. Also:<p><i>&gt; Install the latest Github Release using curl</i><p>Nope.
winkabout 7 years ago
I don&#x27;t get it - looking at the example at <a href="https:&#x2F;&#x2F;github.com&#x2F;fossas&#x2F;fossa-cli?top#quick-start" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;fossas&#x2F;fossa-cli?top#quick-start</a> - that&#x27;s hardly more telling than looking at the original dependency file?<p>Maybe there should be a (more prominent?) link to that rich, hosted example report :)
cjpabout 7 years ago
&gt; for any codebase<p>&gt; Supports over 15+ languages &amp; environments (JavaScript, Java, Ruby, Golang, PHP, etc...)<p>The title here is overly broad, bordering on click bait. I suggest it be edited to &quot;for several popular languages&quot;.
julienchastangabout 7 years ago
+1 for Python (<a href="https:&#x2F;&#x2F;github.com&#x2F;fossas&#x2F;fossa-cli&#x2F;issues&#x2F;13" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;fossas&#x2F;fossa-cli&#x2F;issues&#x2F;13</a>)
tnhmenabout 7 years ago
XiZhao any links that explains tool like I am 5(in a programming sense)? The tool feels like of importance to my current java project.
johnnyoabout 7 years ago
Step One: Get low level developers to upload evidence of major corporate license violations to your server.<p>Step Two: Sell evidence to legal firms.<p>Step Three: Profit.<p>This seems very risky from a company perspective.
评论 #16594876 未加载
评论 #16595123 未加载