We are using Fossa for spring boot applications and for angular UI applications. We are using maven dependencies for the spring boot applications , Fossa scans our spring boot application after running through the pipeline since we have integrated security tools in our tekton pipeline. Fossa identifies all the libraries and dependencies from our gardle and maven. It will show issues, security , quality of the libraries along with the severity and also recommends the fixes for the vulnerabilities. But sometimes fix won't show immediately. Review collected by and hosted on G2.com.
The main thing I like about the fossa is environment specific and alerts if any dependency have security vulnerabilities fossa will send a alert so that we can easily notice vulnerabilities in the project. Review collected by and hosted on G2.com.
The reviewer uploaded a screenshot or submitted the review in-app verifying them as current user.
Validated through LinkedIn
Organic review. This review was written entirely without invitation or incentive from G2, a seller, or an affiliate.