A mid-sized SaaS company discovered their legal team had failed to identify an AGPL-licensed library in their stack. Because AGPL's network copyleft clause required open-sourcing their entire application, they were forced to rewrite six months of work at a cost of ~$300K and a three-month product launch delay.
Sources: Medium case study
LICENSE_RESTRICTION_DERIVATIVE_WORK_COPYLEFT.
| Tool | Verdict | Details |
|---|---|---|
| OSS Risk Guard | Caught | LICENSE_RESTRICTION_DERIVATIVE_WORK_COPYLEFT. |
| Socket | Partial | Has license scanning but not primary focus |
| Snyk | Caught | License compliance scanning |
| Sonatype (Nexus) | Caught | License compliance in Lifecycle product |
| Black Duck | Caught | Industry-leading license compliance; largest knowledge base |
| Endor Labs | Caught | License compliance scanning |