We've been using FOSSA for about six months now, primarily to manage compliance for a B2B SaaS product that integrates with platforms like Google Workspace. I spent a lot of time reading through the documentation and existing threads here before we started, and I wanted to share what the actual day-to-day has been like.
The initial scan and dependency discovery worked as advertised. It gave our engineering team a clear, if somewhat overwhelming, starting point. Where we ran into friction was during the ongoing integration with our CI/CD pipeline. The findings sometimes felt noisy, and it took us a while to fine-tune the policies to distinguish between critical compliance blockers and mere informational alerts. We also had to learn how to handle transitive dependencies effectively.
On the plus side, the audit trail features have been invaluable for our customer success and security questionnaires. Being able to prove due diligence quickly is a real time-saver. I'm curious if others have focused on using it more for the compliance reporting side versus deep developer workflow integration, and what that balance looks like.