Skip to content
Notifications
Clear all

FOSSA pricing feedback - is it cheaper than Mend for 50 devs?

3 Posts
3 Users
0 Reactions
1 Views
(@cloud_infra_newbie)
Reputable Member
Joined: 4 months ago
Posts: 177
Topic starter   [#18290]

Hi everyone,

I'm trying to convince my team to use a proper SCA tool. We're about 50 developers, mostly doing AWS Lambda with Node.js and some container stuff. Right now we're manually checking licenses sometimes, but it's not consistent.

We're looking at FOSSA and Mend (formerly WhiteSource). The sales process is just starting. I've seen some old forum posts but pricing is always vague.

For a team our size, is FOSSA generally more cost-effective than Mend? I'm not sure if we need all the bells and whistles. Our main needs are:
- Open source license compliance (priority)
- Vulnerability scanning for dependencies
- CI/CD integration (we use GitHub Actions)

I found a snippet in a tutorial about setting up FOSSA's CLI, but not sure if this relates to their SaaS pricing:

```bash
# Install and run a basic scan
curl -H 'Cache-Control: no-cache' https://raw.githubusercontent.com/fossas/fossa-cli/master/install.sh | bash
fossa analyze
```

Does anyone have recent experience with quotes for ~50 seats? Just trying to get a ballpark before we get into long calls with sales. Thanks!



   
Quote
(@jackb2)
Eminent Member
Joined: 5 days ago
Posts: 26
 

For 50 devs, FOSSA came in about 30% cheaper for us last year. Their pricing is more per-repo, not per-developer, which can work in your favor if you have a lot of devs working on fewer projects.

That CLI snippet is their free tier, which is limited. For the features you listed, you'll need their SaaS plan. Mend's baseline price was higher but included more policy automation.

Get detailed quotes, but also run a POC on your biggest repo with both. The scan accuracy, especially for Lambda layers and container dependencies, varied a lot. Mend found more issues, but many were low-severity noise. FOSSA was faster in CI.


Benchmark or bust


   
ReplyQuote
(@frankd)
Eminent Member
Joined: 4 days ago
Posts: 23
 

That CLI snippet is definitely their free tier, which is great for a quick test but won't handle your license compliance needs. It's more of a demo for the scanning engine.

On pricing for 50 devs, user1354's point about per-repo vs. per-developer is key. Your structure matters a lot. If your 50 devs are working on, say, 10 core repos, FOSSA's model could be significantly cheaper. If you have dozens of separate microservice repos, the cost might even out or flip. When you get those quotes, have your repo count ready.

One caveat on the "30% cheaper" point - that was last year. Mend has been aggressive with discounts, especially if you're also looking at their container or SAST tools. Don't be shy about asking for their best price to compete; you might be surprised how much they can move.

For your main needs, both will cover the bases. The real differentiator for your stack will be how cleanly they handle Lambda layers and nested container deps. That's where some tools generate a lot of false positives or miss things entirely. A POC is non-negotiable.


buyer beware, but buy smart


   
ReplyQuote