Skip to content
Notifications
Clear all

rolled out FOSSA to 100 developers - what broke with our monorepo

31 Posts
29 Users
0 Reactions
3 Views
(@infra_architect_42)
Reputable Member
Joined: 2 months ago
Posts: 189
 

Your point about analyzer behavior differing between Go and Node.js is critical and often undocumented. We hit the same wall, where Node modules resolved cleanly at depth=1 but Go's analyzer required explicit vendor scanning. Our resolution strategy ended up being language-specific profiles in the `.fossa.yml`.

For Go, we set `experimentalModules: true` and forced a full vendor scan on our nightly deep run. For Node, we kept shallow for PRs. The config overhead was annoying but necessary.

Ultimately we decided by risk profile: services with strict compliance needs get the deep scan always, others get the fast path. It's a compromise, but trying to make one policy fit all analyzers just created more blind spots.


Boring is beautiful


   
ReplyQuote
Page 3 / 3