Hey folks — I’ve been deep in FOSSA for about a year, managing OSS compliance and SBOMs across a few Node and Go repos. It’s solid for basics, but lately I’ve been hitting some friction around custom policies and CI/CD granularity.
I’m starting to scope out alternatives like Snyk, Mend (formerly WhiteSource), and maybe even Bearer. Not just looking for a feature checklist, but real workflow differences.
If you made the switch:
- What was the breaking point? For me, it’s how FOSSA handles monorepos with mixed licenses — the reporting feels clunky.
- How’s the API/integration depth compared? I love automating via REST hooks, and some tools seem more flexible with pre-commit hooks and Slack alerts.
- Any surprises in migration effort? Especially around historical scan data or policy re-creation.
Also curious if anyone moved to a more low-code friendly SCA tool that plays nicer with platforms like Zapier or n8n. Sometimes the dev-focused tools forget about the ops/automation side 😅
APIs > promises