
Automate open source license compliance and software supply chain integrity
DejaCode is an enterprise-level application by nexB that automates open source license compliance and ensures software supply chain integrity. Powered by ScanCode, it lets you track all open source and third-party components, generate SBOMs in CycloneDX and SPDX formats, apply usage policies, and produce compliance artifacts including attribution documentation. Available as both a cloud-hosted SaaS and on-premises installation, it integrates with VulnerableCode for vulnerability tracking and PurlDB for package reference data.
Automatically track and enforce license obligations across your software portfolio
Identify all open source and third-party components in your codebase
Create, publish and share software bill of materials in industry-standard formats
Leverage the industry-leading ScanCode engine for deep code and license detection
Monitor aggregated vulnerability data for all tracked components
Access comprehensive public reference data for packages and licenses
Apply and enforce usage policies at the license or component level
Produce attribution documentation and custom compliance reports in multiple formats
Maintain a complete history of compliance decisions and changes for audits
Full REST API enabling integration with CI/CD pipelines and enterprise systems
Event-driven automation via webhooks for real-time workflow integration
Native integration with GitHub for seamless DevOps compliance workflows
Deploy as a cloud-hosted service or install on your own infrastructure
Generate detailed reports in multiple file formats tailored to your needs
Try the full platform with a private 30-day trial at no cost