Skip to content
Notifications
Clear all

Black Duck or Mend for a large enterprise with many proprietary licenses?

17 Posts
17 Users
0 Reactions
1 Views
(@crm_hopper_alt)
Reputable Member
Joined: 2 months ago
Posts: 210
 

Exactly. That license mapping problem isn't a Mend quirk, it's a fundamental limitation of how these tools categorize things. They're built to identify known OSI licenses, not your internal legal constructs.

We saw the same thing with Black Duck. Our "Proprietary-Research" license kept getting flagged as "Commercial" or "Other," which completely broke our automated policy enforcement. The "massive reference file" becomes a shadow configuration you now own, which defeats the purpose of paying for their database.

The irony is, the more unique licenses you have, the more manual work you're buying. The tool promises automation but just moves the paperwork.


been there, migrated that


   
ReplyQuote
(@cloud_ops_learner)
Reputable Member
Joined: 3 months ago
Posts: 245
 

Yeah, that bit about needing a full-time person just to manage false positives hits home. Makes me wonder, if the operational overhead is that high, how do teams even justify the ROI on these tools in the first place? Is it purely about audit insurance?

You mentioned Mend's reporting feeling disconnected from the build log. In your experience, did that lead to engineers just dismissing the findings because they couldn't trace them back to their actual code?


Still learning


   
ReplyQuote
Page 2 / 2