Black Duck has performed thousands of open source audits for M&A due diligence. Their 2025 OSSRA report found 85–89% of transactions contain license compliance risks, 96% of applications contain unpatched vulnerabilities, and 65% have GPL-specific conflicts. Deal repricing of 1–10% is common when significant copyleft contamination is discovered.
Sources: Black Duck OSSRA report
PACKAGE_LICENSE_MISMATCH + PACKAGE_NO_LICENSE + LICENSE_NOT_APPROVED; continuous automated scanning with dollar quantification
| Tool | Verdict | Details |
|---|---|---|
| OSS Risk Guard | Caught | PACKAGE_LICENSE_MISMATCH + PACKAGE_NO_LICENSE + LICENSE_NOT_APPROVED; continuous automated scanning with dollar quantification |
| Socket | Partial | License scanning exists but not M&A-focused |
| Snyk | Partial | License scanning exists but no M&A reporting |
| Sonatype (Nexus) | Partial | License scanning exists but no bonded M&A reports |
| Endor Labs | Partial | License scanning exists but no M&A focus |
| Black Duck | Caught | Industry standard for M&A audits; qualitative reports at $30-100K per codebase |