SCANOSS’s Earnie catches the license violations AI coding agents don’t know they’re creating
The major release checks license obligations down to the copied snippet — in context via MCP, at pre-commit, and at
Press Release Disclaimer: This is a press release distributed through the XPR Media network. It has not been independently verified by our newsroom.

![]()
The major release checks license obligations down to the copied snippet — in context via MCP, at pre-commit, and at merge — for code moving at agent speed.
MADRID, MADRID, SPAIN, October 6, 2026 /EINPresswire.com/ — As AI coding agents take on a growing share of enterprise development, open source license obligations are entering codebases faster than most compliance programmes can review them: an agent has no visibility into a team’s license policy, and no reason to pause and check one. SCANOSS today announced the public launch of Earnie, a major release of its software governance platform, at a live online event. Earnie is a continuous programme, organised around dated Releases rather than a point-in-time scan, for a world where code, including AI-written code, moves faster than manual review can follow.
A human developer who copies a snippet from a forum post might pause, half-remember something about a copyleft license, and ask a colleague before committing it. A coding agent won’t. It has no memory of a company’s license policy, no instinct that a snippet might carry an obligation, and no reason to flag what it just wrote. As agents generate and commit code at a volume no human review process was built to keep pace with, that gap stops being one violation at a time and becomes exposure at scale — quietly, across dozens of commits a day.
Earnie is built to close that gap at the same speed the exposure is created. It catches license obligations down to the individual snippet — not just the declared dependency a typical software composition analysis tool would see — across a developer’s own commits, copied or vendored code, and anything an AI agent introduces, using the same deterministic, KB-backed detection across all three.
For each component Earnie identifies, it maps the applicable license and its obligations, generates attribution and notice files, and keeps a versioned software bill of materials (SBOM) in open standards (CycloneDX and SPDX) ready for export on demand. An existing CycloneDX or SPDX SBOM can also be imported directly, so a team doesn’t have to rebuild its inventory from zero. The result is a standing record of license posture rather than a report that goes stale the day after it’s produced.
Detection is only the starting point. Earnie connects each finding to policy, so a team can see not just what was found but what to do about it, and to a record of the decision itself: policy changes go through an approval step with a visible pending, approved, or rejected status, so a change in what’s allowed is as auditable as the finding that prompted it.
Earnie also brings this checking directly into the coding-agent workflow. Over the Model Context Protocol (MCP), a coding agent can ask Earnie whether a component is allowed under a project’s policy before it ever adds the dependency, and receive guidance — pass, warn, or flag for review — in the same moment it’s writing code. The same policy applies again once a change reaches a pull request, where it appears as a clear comment and pass/warn signal for the reviewer.
– MCP: in-context policy guidance for coding agents, before a dependency is added
– CLI and pre-commit: license and obligation checks at the keyboard
– GitHub Actions and pull-request checks: policy comments and pass/warn signals on every PR
– Earnie UI: the standing record of findings, decisions, and evidence
Earnie’s detection draws on SCANOSS’s proprietary knowledge base of more than 188 million open source components and 3 trillion lines of fingerprinted code across 12 programming languages, with no dependency on third-party data. Each customer works in its own isolated environment; source code stays there, and only fingerprints and hashes are shared with SCANOSS for matching.
SCANOSS says the goal is a record that satisfies a stricter test than a compliance checklist: results a team can trust internally, and results a regulator or auditor can independently audit.
Earnie is available now. Details on the full release, including coverage of AI governance and post-quantum cryptography readiness, are available at earnie.dev.
SCANOSS Communications
SCAN OPEN SOURCE SOLUTIONS SL
Visit us on social media:
LinkedIn
YouTube
Meet Earnie: governance that keeps up with agent-written code
Legal Disclaimer:
EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.
![]()
Media gallery


