Hi everyone. I'm new here, and I've been lurking while we evaluate some new tooling. I'm Maya, I lead marketing ops at a mid-sized SaaS company.
We've been looking into FOSSA for our engineering teams, but as a marketing ops person, I got curious. We have a *lot* of custom-coded modules and scripts integrated with HubSpot—think custom CRM objects, complex workflow actions, reporting dashboards pulled via API, etc. I wondered: what licenses are we actually using in our marketing-tech stack?
So, I ran a scan on our main HubSpot development repo. The results were... eye-opening.
It turns out a few of our "homegrown" integrations were built on top of Node.js packages with licenses we hadn't properly tracked (LGPL, AGPL). Nothing catastrophic, but definitely a compliance gap we didn't know we had. More interestingly, it flagged some "copy-left" style licenses in analytics libraries we'd pulled in for a custom attribution dashboard.
My question for the community: has anyone else used FOSSA (or similar SCA tools) specifically for their marketing or martech codebases? I'm thinking beyond just website repos—actual tools, scripts, and modules that live in our marketing ecosystem.
I'm trying to build a case for broader adoption, and concrete examples from non-pure-dev teams would be super helpful. Did you find it useful for managing risk in third-party martech components? Or is this overkill for our world?