WhiteSource Releases JNinka- Free Source Code Scanner for License Discovery
The new free source code scanner identifies open source code hidden within your own proprietary code.
WhiteSource, the leading provider of SaaS Open Source Lifecycle Management Solutions, announced the release of JNinka- free source code scanner for license discovery. JNinka is released as a fully open source code, under the AGPL license. The software is based on the Ninka algorithm. It works by scanning the code for common license, copyright, and other notes.
WhiteSource provides simple to use, yet powerful solutions for companies that need to manage their open source assets to ensure license compliance and reduce risk. Developers and managers use WhiteSource’s solutions to track, audit and report on open source components throughout the software development lifecycle.
The new free open source scanner identifies open source code hidden within your own proprietary code. The scan runs locally, keeping the scanned code fully secure. The results of the scan may also be imported into WhiteSource cloud-based open source lifecycle management service, to be managed alongside other open source components.
The JNinka scanner is ideal for searching for open source code components that were cut and pasted into proprietary code, and were inadvertently not reported. Since it is based on common texts, the scanner does not require access to a huge and up to date database, and hence can be run off line, very quickly, and in private. The scanner produces an XML that can optionally be consumed by WhiteSource’s open source lifecycle management service.
“Some licenses permit copying source code text, but require notification and proper management. The JNinka tool reveals these open source licenses “. said WhiteSource CEO Rami Sass .”The JNinka scanner represents another step in WhiteSource’s mission to help software developers manage their usage of Open Source”.
The new free source code scanner is based on the Ninka project.

About Mend.io
Mend.io offers the first AI native application security platform, empowering organizations to build and run a proactive AppSec program tuned for AI powered development. The unified platform secures AI generated code and embedded AI components, drives risk reduction through AI powered remediation, automates compliance, and provides a holistic enterprise scale view of risks and clear actions for developers across your entire codebase.