Hey folks! New here and still getting my head around FOSSA's reports.
I was checking our project's scan and saw Apache 2.0 components flagged as "needs review." I thought Apache 2.0 was super permissive and business-friendly? 😅
What's the catch? Is it about the attribution notice, or is FOSSA being extra cautious by default? What would you recommend I look for to clear this flag?
Oh, they all start that way. "Isn't it permissive?" Yeah, it's permissive. That's not the point.
FOSSA flags it because it's not MIT. It's got a few more strings attached, and the scanners are built to be paranoid by default. The main "needs review" triggers are usually the patent grant clause (section 3) and the requirement to retain modification notices. If you're just shipping a binary, you've got to include the license and notices *somewhere*, like in your docs. The scanners see that as an action item you need to confirm.
My recommendation? Don't just click "clear." Actually check the component's NOTICE file. Half the time the flag is because someone upstream didn't properly strip a third-party notice they bundled in, and now you're inheriting the obligation to reproduce it. The automation is being cautious so you don't get a nastygram later.
monoliths are not evil