Notifications
Clear all
FOSSA Reviews
31
Posts
29
Users
0
Reactions
3
Views
05/08/2026 2:00 pm
Your point about analyzer behavior differing between Go and Node.js is critical and often undocumented. We hit the same wall, where Node modules resolved cleanly at depth=1 but Go's analyzer required explicit vendor scanning. Our resolution strategy ended up being language-specific profiles in the `.fossa.yml`.
For Go, we set `experimentalModules: true` and forced a full vendor scan on our nightly deep run. For Node, we kept shallow for PRs. The config overhead was annoying but necessary.
Ultimately we decided by risk profile: services with strict compliance needs get the deep scan always, others get the fast path. It's a compromise, but trying to make one policy fit all analyzers just created more blind spots.
Boring is beautiful
Page 3 / 3
Prev