Revenera Code Insight is a commercial software composition analysis platform for open-source discovery, license compliance , vulnerability monitoring, and inventory review.
Revenera’s current product page advertises a data library with more than 14 million components, support for over 25 languages, and more than 70 extensions. It names NVD and Secunia Research among the product’s vulnerability sources.
Code Insight scans source code, binaries, containers, build dependencies, subcomponents, and modified or partial open-source components. License and security policies can automatically review discovered inventory, while unresolved items remain available for manual review.
What is Revenera Code Insight?
Code Insight builds an inventory of open-source and third-party components found in a software project. Development, legal, and security teams can review license evidence, vulnerabilities, policy decisions, remediation notes, and release notices in the same system.
Is FlexNet Code Insight the same product?
Flexera introduced Revenera as the new name for its supplier-focused division in May 2020. Revenera remains part of Flexera.
The product also dropped βFlexNetβ from its official name during the 2020 rebrand. Current product pages and 2026 R2 documentation call it Code Insight, although the legacy name remains common in searches and older documents.
What are Revenera Code Insight’s key features?
Supported ecosystems
Code Insight’s current ecosystem matrix documents support by artifact and dependency level. Coverage is not uniform across every format.
| Ecosystem | Documented inputs |
|---|---|
| Java | Maven and Gradle files, JARs |
| Node.js | npm and Yarn manifests and lockfiles |
| Python | requirements, setup, wheel, egg, metadata, and pyproject files |
| C/C++ | source files, Makefiles, CMake, Conan, and Debian packages |
| Go | modules, legacy manifests, and Go binaries |
| .NET | project files, packages, and PE binaries |
| PHP | Composer manifests and lockfiles |
| Ruby | Gem files, Gemfiles, and gemspecs |
| Rust | Cargo manifests, packages, and lockfiles |
| Swift/Objective-C | CocoaPods files |
| Containers | Docker images and Dockerfiles |
License compliance management
Code Insight records license evidence found during scanning and links recognized licenses to obligation information. License policies can approve, reject, or route inventory for review, and current releases distinguish commercial from open-source licenses.
Deep code scanning
Server scan profiles can enable source-code matching against snippets in the Compliance Library. They can also use exact-file matches, license text, copyrights, URLs, emails, package metadata, and other evidence to identify inventory.
Source matching is configurable rather than universal. The profile controls which files are eligible and how many snippet matches must be found before a file is reported.
IP risk assessment
The inventory and license workflow can surface copyleft obligations, missing notices, and components that need legal review. Revenera markets these outputs, together with its partner-delivered audit services , for M&A due diligence.
Legal workflow integration
Policies can automatically review inventory based on license or security criteria. Items that do not match a policy can be reviewed manually by legal or security specialists, with remediation and usage guidance kept on the inventory record.
SBOM generation
Code Insight constructs a reviewed component inventory and can export it to the separate Revenera SBOM Insights product. It can also import CycloneDX or SPDX data into a configured project.
The product’s standard reports are Project, Audit, and Notices reports. Current documentation does not list CycloneDX or SPDX as direct Code Insight report outputs, so those formats are not marked as native exports here.
Transitive dependencies and reachability
Scan profiles can request no dependencies, first-level dependencies, or all transitive dependencies. Actual results depend on the ecosystem and input files; the official matrix marks direct and transitive support separately for each format.
The current product documentation does not describe call-graph reachability or automated fix pull requests. Code Insight instead tracks vulnerable inventory, alerts, policy decisions, and remediation guidance.
Installation
Code Insight 2026 R2 uses Core Server and Scan Server components. Revenera’s installation guide covers supported operating systems, databases, sizing, installation, upgrades, and server configuration.
The quick-start path creates a project, uploads a codebase to a Scan Server, applies a scan profile, runs the scan, reviews inventory, completes remediation, and generates a Notices report. Remote scans use a plugin installed in the relevant build or CI environment.
What does Revenera Code Insight integrate with?
CI/CD Pipeline Integration
The current plugin guide lists Azure DevOps, Bamboo, GitLab, Jenkins, and TeamCity integrations. Package and build plugins cover Ant, Gradle, and Maven, while the Docker Images plugin scans container images.
The generic scan-agent plugin scans arbitrary file systems and can be used from other engineering systems. It runs as a versioned Java archive, authenticates with a Code Insight JWT, and sends results back to a project for policy or manual review.
IDE Integration
Current documentation lists plugins for Eclipse workspaces and Visual Studio solutions. It does not list native VS Code or IntelliJ plugins.
APIs and other integrations
Code Insight provides REST APIs for custom integrations. The product page also documents integration categories for source control, artifact repositories, build tools, and issue tracking without claiming that every third-party system has a native plugin.
Setup
When to use Revenera Code Insight
Code Insight fits organizations that need scanned evidence, component inventory, policy review, vulnerability monitoring, and release notices in one SCA workflow. Revenera also positions its SCA portfolio for software due diligence and regulated product teams.
Strengths:
- More than 14 million components in the vendor’s current data library
- Source-code, binary, container, and dependency scanning
- License and security policy review
- Project, audit, and Notices reports
- Server, CI, build, IDE, generic-agent, and REST integration options
Limitations:
- Heavier setup than developer-first tools
- Dependency depth varies by ecosystem and artifact
- No documented call-graph reachability
- No documented automated fix-pull-request workflow
Further reading: Open Source License Compliance | What is SCA? | What is SBOM?
Revenera vs Snyk, Sonatype, and Black Duck
Snyk Open Source , Sonatype Lifecycle , and Black Duck overlap with Code Insight on component, license, vulnerability, and policy analysis. Their deployment models, reachability features, remediation automation, repository controls, and legal-review workflows differ.
No current vendor-independent benchmark was found that supports a universal accuracy, database-size, workflow-depth, or βbest for M&Aβ ranking among these products. Compare them with the same codebase, scan scope, policy set, and review criteria.
The open-source SCA tools and open-source license compliance guides provide broader context.
