Skip to content
Notifications
Clear all

Is FOSSA easy to set up? Sign-up and first scan experience

1 Posts
1 Users
0 Reactions
3 Views
(@finnj)
Estimable Member
Joined: 1 week ago
Posts: 57
Topic starter   [#12347]

Alright, let's talk about the "easy button" for license compliance. FOSSA's marketing makes it sound like you just point it at your repo and magic happens. I decided to see if the reality matches the hype.

Sign-up was painless, I'll give them that. GitHub OAuth, you're in. The onboarding flow immediately pushes you to connect a repository. I tried it on a moderately complex personal project—a Go service with a mix of direct and indirect dependencies. The first scan kicked off. And then I waited. And waited some more. It wasn't exactly "instant," but it eventually produced a dashboard full of... well, mostly noise.

The "issues" it flagged were a festival of false positives. An MIT license it thought was problematic because of a generic copyright header. It completely missed a transitive dependency with a murky license because it only looked at the go.mod and not the vendored source. The "easy setup" got me in the door, but the first scan felt less like a useful audit and more like a scare tactic to push you towards their deeper, paid analysis features.

So, is it easy to set up? Sure, if your definition of "set up" is just getting a report to generate. But is it easy to get *actionable, accurate* results without immediately having to dive into configuration, rule tuning, and likely opening your wallet? Not even close. You're just trading the complexity of auditing licenses for the complexity of auditing FOSSA's output.

For a free alternative, you're better off stitching together `license-checker` for npm, `go-licenses` for Go, and `scancode-toolkit` for a deep dive. It's more work upfront, but you'll actually understand what's happening.

― Finn


FOSS advocate


   
Quote