You're on the right track with Licensee and scancode-toolkit for detection. We evaluated that exact approach last year. The detection accuracy for straightforward packages is good, but you'll spend significant engineering time building the logic to handle edge cases like multi-license files, 'OR' conditions, and the specific formatting in Go `vendor` directories. scancode-toolkit is incredibly thorough, but slow for CI.
For a small project, I'd start with scancode for a baseline and use its SPDX JSON output. But your instinct about only using a paid tool for resolution is spot-on - that's the real value. We ended up using Mend's API solely for its policy engine and remediation advice on flagged licenses, feeding it the raw dependency list we gathered ourselves. That kept costs 70% lower than a full seat license.
The internal consolidation service is indeed work, but you can start minimal: a scheduled job that pulls the JSON artifacts from your CI system and runs a simple Python script to deduplicate and output a CSV. It doesn't need to be a service on day one.
—chris
Spot-on about the 3-year fixed price quote. That's become the only way to contain the creep. My last renewal negotiation took that path, and we locked in a 70% cap on any increase for year three.
But you've got to watch the definitions in that contract, especially around what constitutes a "scan." Some vendors are now counting every pipeline run, not just unique repos.
Trust the data, not the demo.
That snippet does look clean. I've been looking at FOSSA too, but the monorepo snag you mentioned has me worried. How bad is the bill creep exactly? Is it more about the number of repos or the frequency of scans?
I'm also curious about the newer tools. Has anyone tried out Snyk's license-only tier recently? The thread says it's just detection, but their docs talk about some remediation features.
> Is it more about the number of repos or the frequency of scans?
Both. Vendors have gotten clever. If you're triggering scans on every PR, you're in for a shock. We caught a 40% price hike proposal because they started counting every scan on a unique commit, not just unique projects.
Snyk's license tier is decent for detection and has basic policy blocks, but their "remediation" is just links to their KB articles and upgrade suggestions. It won't auto-suggest alternative libraries like Mend or FOSSA does. For Python/Go, it's okay as a budget scanner, but you'll still need manual work for actual fixes.
Run it yourself.