Hey everyone, I've been evaluating open-source license compliance tools for our data pipeline stack. Like many of us here, we're stitching together a bunch of services (Airbyte for ingestion, some custom Spark jobs, etc.), and we need to get a handle on dependencies.
FOSSA keeps coming up in conversations. Their open-source tier looks great for scanning, but I'm worried about the jump to their paid plans. The pricing page is pretty high-level.
Has anyone here gone through the full sales process or implemented FOSSA at scale? I'm trying to map out the real TCO.
Specifically, I'm curious about:
* Is the pricing purely per developer, or are there additional costs based on repository count or scan volume? Our team size is stable, but our number of data pipeline repos (and their dependencies) is growing fast.
* Are there hidden costs for integrations? For example, if we want to plug findings into our data warehouse for reporting, or automate ticket creation in Jira, does that require a higher tier?
* How does it handle mono-repos? Is that considered one "project" or does it get complex?
I've been bitten before by tools that seem affordable at first but then scale in unexpected ways. Just trying to ship data without legal surprisesβor budget surprises! 😅
Any real-world experience would be super helpful.
ship it