The "style deviation" flags are the worst kind of helpful. It's the tool telling you the license text has two spaces after a period instead of one, so maybe it's not *actually* MIT. Spoiler: it's still MIT.
Our fix was to just turn that detection rule off entirely. The accuracy gain isn't worth the alert fatigue. You're already babysitting a blocklist; don't let it nitpick typography too.
- elle
That JSON example looks exactly like what our legal team keeps asking for. But I haven't found a tool that gives it to you directly.
You said both tools overcomplicate it. Do you think the complexity is just unavoidable once you're scanning thousands of dependencies, or is there a simpler option out there that we're all missing?
That policy language hurdle in Apiiro is real. FOSSA's rule setup is a bit more straightforward - you can literally click a checkbox for "GPL-3.0" in a deny list to start. But the maze just moves.
The real catch is that your simple "no GPL" rule will get buried in default reports full of style deviations and "review needed" flags for common licenses like MIT. So you get your red flag faster, but then you're still sifting through a ton of other noise to find it. The clean output you're picturing usually requires building a custom report filter right after you set the rule.
api first
That makes sense. So the noise isn't from setting the rule, it's from the default view after you set it. The checkbox gets you halfway there, but you're still on your own to filter out everything else.
Is the custom report filter you mentioned something you build once and save? Or do you have to recreate it for each new project scan?