Skip to content
Notifications
Clear all

My results after running FOSSA on a legacy Java codebase: 200+ license issues, now what?

3 Posts
3 Users
0 Reactions
1 Views
(@emmab5)
Eminent Member
Joined: 1 week ago
Posts: 33
Topic starter   [#17936]

Hi everyone. I'm new to FOSSA and just ran my first scan on a big, old Java project my team inherited. I was... not prepared for the output.

It found over 200 license issues! Mostly things like "license not found" or "conflicting licenses" in dependencies. It feels like a huge mess to untangle. Has anyone else been in this situation? Where do you even start? Do you go through each one manually, or is there a better workflow in FOSSA itself for triaging something this big? I'm a bit lost on the next practical steps.



   
Quote
(@hannahg)
Estimable Member
Joined: 1 week ago
Posts: 71
 

Oh wow, welcome to the club, haha. That first FOSSA report on an old codebase is always a shock.

First, breathe. Don't try to tackle all 200 manually. In FOSSA, you need to start by filtering and grouping. Click into the issues view and use the filters for "policy" or "severity." Group by "license not found" first, because those are often the quickest wins. Sometimes it's just a metadata issue in the dependency, and FOSSA can be taught to recognize it.

Your real goal right now isn't to fix everything, it's to get a handle on the biggest risks. Look for any "GPL" licenses in that "conflicting" pile, as those can be a higher priority than, say, a bunch of MIT/BSD conflicts. Triage the scary ones, make a simple spreadsheet for your team, and then chip away at the rest over sprints. You got this! 😅



   
ReplyQuote
(@hannahr2)
Eminent Member
Joined: 4 days ago
Posts: 16
 

Spot on about filtering. That's the only way to stay sane. I'd take that "group by license not found" advice one step further.

Within that filter, sort by depth in your dependency tree. A top-level "license not found" in something you directly declared is your problem to solve. But a deep, transitive one buried five libraries down? That's *their* problem, and it often gets auto-fixed upstream in a future release. I'd annotate those in FOSSA and set them to "ignore for now" with a 3-month review reminder. Saves you chasing ghosts.

Your point about prioritizing GPL conflicts is the real key. I'd add: run a quick export of just those high-risk issues. A raw CSV into a shared doc with columns for "Dependency," "Issue," "Our Action," and "Owner" has saved my team countless hours. It turns a scary list into a manageable project plan. Let us know how the triage goes


Measure twice, automate once.


   
ReplyQuote