SCANOSS Earnie targets license blind spots in AI-generated code

SCANOSS Earnie targets license blind spots in AI-generated code

–

The flagship update tracks license duties down to the exact copied snippet — via MCP in real time, at pre-commit, and when merging — for code moving at machine pace.

An agent commits as quickly as it produces tokens, with zero awareness of your policies. Earnie ensures obligations aren't missed simply because human review hasn't kept up.— Julian Coccia, CEOMADRID, MADRID, SPAIN, October 6, 2026 /EINPresswire.com/ — With AI coding agents handling an expanding portion of enterprise development, open source license requirements are streaming into codebases at a pace most compliance operations can't match: an agent has no insight into a team's licensing rules, and no incentive to halt and verify one. SCANOSS revealed the general availability of Earnie, a significant upgrade to its software oversight platform, during a live webcast. Earnie operates as a continuous framework, structured around dated releases instead of a one-off scan, designed for an environment where code — including AI-generated code — outruns any manual review process.

A human coder who lifts a fragment from an online discussion might hesitate, vaguely recall something about a copyleft license, and consult a teammate prior to submitting it. A coding agent won't. It carries no recollection of an organization's licensing rules, has no intuition that a snippet may impose an obligation, and sees no reason to signal what it just produced. As agents generate and push code in volumes no human review system was designed to handle, that shortfall shifts from isolated incidents to systemic vulnerability — silently, across dozens of daily commits.

Earnie aims to close that void at the same velocity the risk is generated. It flags license duties down to the individual snippet — not merely the declared dependency that conventional software composition analysis would catch — spanning a developer's own commits, copied or vendored code, and anything an AI agent contributes, applying the same deterministic, knowledge-base-driven detection across all three.

For every component Earnie detects, it determines the relevant license and its requirements, produces attribution and notice documents, and maintains a versioned software bill of materials (SBOM) using open formats (CycloneDX and SPDX) ready for on-demand export. A pre-existing CycloneDX or SPDX SBOM can be loaded directly, sparing a team from reconstructing its inventory from scratch. The outcome is an ongoing record of licensing position rather than a snapshot that goes obsolete the moment it's generated.

Detection is merely the beginning. Earnie links each discovery to policy, enabling a team to see not just what was uncovered but the appropriate response, plus a log of the decision itself: policy modifications pass through an approval workflow with clear pending, approved, or rejected status, making any shift in permitted usage as traceable as the finding that triggered it.

Earnie also embeds these checks directly into the coding-agent pipeline. Through the Model Context Protocol (MCP), a coding agent can query Earnie about whether a component is permissible under a project's policy prior to adding the dependency, and receive feedback — pass, warn, or flag for review — at the exact moment it's composing code. The same rules are applied again when a change reaches a pull request, where it appears as a concise comment and pass/warn indicator for the reviewer.

– MCP: real-time policy direction for coding agents, before a dependency is introduced
– CLI and pre-commit: license and obligation checks directly at the keyboard
– GitHub Actions and pull-request checks: policy comments and pass/warn indicators on every PR
– Earnie UI: the persistent record of findings, choices, and supporting evidence

Earnie's detection relies on SCANOSS's in-house knowledge base containing over 188 million open source components and 3 trillion lines of fingerprinted code across 12 programming languages, with no reliance on external data sources. Each customer operates within its own isolated environment; source code remains there, and only fingerprints and hashes are transmitted to SCANOSS for comparison.

SCANOSS states the objective is a record that meets a more rigorous standard than a compliance checklist: results a team can rely on internally, and results that a regulator or auditor can independently verify.

Earnie is now live. Complete information on the full rollout, including AI governance and post-quantum cryptography preparedness, is accessible at earnie.dev.

SCANOSS Communications
SCAN OPEN SOURCE SOLUTIONS SL
Visit us on social media:
LinkedIn
YouTube

Meet Earnie: governance that keeps up with agent-written code


David Hall

David Hall

David is the senior editor at TheCyberMag. He has a background in journalism and has worked with various media outlets, covering topics ranging from threat intelligence and data privacy to cybercrime and cloud security. When he is not writing, David enjoys reading, hiking, photography, and exploring new coffee shops.