Skip to content
You must be logged in to sponsor nexB

Become a sponsor to nexB

@nexB

nexB

California, USA

Support our work building and maintaining critical open source Software Composition Analysis (SCA) and SBOM tools to help developers and organizations effectively use open source software and comply with FOSS licenses, manage dependencies and track known vulnerabilities.

AboutCode is a community of open source developers making open source easier to use by building open source tools for SCA - it is also the collective name for these tools.

We maintain key open source projects on GitHub to discover, identify, and track open source software components origin license and vulnerabilities, including standards like Package URL (PURL), databases like the LicenseDB (in ScanCode), VulnerableCode for vulnerabilities and PurlDB for packages, applications like ScanCode.io, tools like the industry leading ScanCode Toolkit, and libraries like python-inspector, container-inspector, debian-inspector and license-expression.

nexB is the primary sponsor of AboutCode, contributing code and support for the open source community. nexB offers commercial software provenance analysis services for organizations, and is committed to helping build and maintain the very best open source SCA tools out there.

Sponsoring AboutCode projects helps us provide financial support to core contributors and external contributors working on these industry leading and critical tools, data and standards. In particular, we maintain a roadmap for each project and your support will contribute directly to bug fixing and new feature developments. Is there something in particular that you would like your funding to support? Please reach out!

You can contact us with any questions at [email protected], chat with us on Matrix / Gitter at https://matrix.to/#/#aboutcode-org_discuss:gitter.im or enter an issue in one of our projects.

Thank you in advance for your generosity.

Current sponsors 1

@mercedes-benz

Past sponsors 1

@pylapp

Meet the team

Featured work

  1. nexB/scancode.io

    ScanCode.io is a server to script and automate software composition analysis pipelines with ScanPipe pipelines. This project is sponsored by NLnet project https://nlnet.nl/project/vulnerabilitydata…

    Python 91
  2. nexB/scancode-toolkit

    🔍 ScanCode detects licenses, copyrights, dependencies by "scanning code" ... to discover and inventory open source and third-party packages used in your code. Sponsored by NLnet project https://nln…

    Python 1,983
  3. nexB/vulnerablecode

    A free and open vulnerabilities database and the packages they impact. And the tools to aggregate and correlate these vulnerabilities. Sponsored by NLnet https://nlnet.nl/project/vulnerabilitydatab…

    Python 475
  4. nexB/purldb

    Tools to create and expose a database of purls (Package URLs). This project is sponsored by NLnet project https://nlnet.nl/project/vulnerabilitydatabase/ and nexB for https://www.aboutcode.org/ Cha…

    HTML 29
  5. nexB/container-inspector

    container-inspector is a suite of analysis utilities and command line tools for Docker container images, their layers and how these relate to each other. It can also handle OCI images and Dockerfiles.

    Python 30
  6. nexB/license-expression

    Utility library to parse, normalize and compare License expressions for Python using a boolean logic engine. For expressions using SPDX or any other license id scheme.

    Python 52

Select a tier

$ a month

A Public Sponsor achievement will be added to your profile.