Quick Start¶
Get from zero to your first compliance scan in under 5 minutes.
1. Install¶
Verify the installation:
Prefer Docker?
If you want the full stack (API + Dashboard + Workers), see the Installation Guide for Docker instructions.
2. Scan a Project¶
Point LCC at any local project directory:
Or scan a remote GitHub repository directly:
Expected output:
Scanning /path/to/your/project...
Found 3 manifest files
Detected 47 dependencies
Results:
MIT : 32
Apache-2.0 : 10
BSD-3-Clause : 3
ISC : 2
✓ Scan complete. No policy violations found.
3. View Results¶
Get a detailed report with the --format flag:
Or export to JSON for programmatic use:
4. Generate an SBOM¶
Create a Software Bill of Materials in CycloneDX or SPDX format from your scan report:
# CycloneDX format (JSON)
lcc sbom generate results.json --format cyclonedx --output sbom.json
# SPDX format (JSON)
lcc sbom generate results.json --format spdx --output sbom.spdx.json
5. Check Against a Policy¶
Enforce compliance rules by scanning with a policy file:
Example policy file (my-policy.yml):
name: proprietary-safe
description: Block copyleft licenses in proprietary projects
rules:
- license: GPL-3.0-only
action: deny
- license: AGPL-3.0-only
action: deny
- license: GPL-2.0-only
action: warn
Expected output with violations:
Scanning /path/to/your/project...
Found 47 dependencies
⚠ Policy Violations:
DENY : some-package@1.2.0 — GPL-3.0-only
WARN : another-pkg@0.9.1 — GPL-2.0-only
✗ Scan complete. 1 deny violation, 1 warning.
Next Steps¶
| Topic | Link |
|---|---|
| All installation methods (Docker, pip, source) | Installation Guide |
| Full CLI reference and configuration options | User Guide |
| Creating and managing compliance policies | Policy Guide |
| REST API for CI/CD integration | API Reference |
| Deploy the full stack to production | Deployment Guide |