Just spent three days with an auditor going through a Black Duck compliance report. It was a waste of everyone's time.
The canned reports spit out every single license, even ones with zero risk (like MIT, BSD). It buries the actual issues—like a lone GPL component—in 200 pages of noise. Auditors need a clear, actionable summary: "Here are the components with potential copyleft obligations." Not a raw data dump.
We ended up having to:
* Filter out all permissive licenses manually.
* Cross-reference the "problem" components against our own bill of materials to confirm we'd flagged them internally.
* Rebuild the report in a simple spreadsheet with columns for Component, License, Status (Approved/Needs Review), and Our Justification.
If I'm paying for a "compliance" tool, the report should be auditor-ready. The benchmark is simple: can I hand this directly to a legal or compliance team without prep work? Black Duck fails.
Anyone else just scripting around this to pull the real data you need? What's your workflow?