Almost certainly true. I doubt the Sparrow developers were deliberately misusing the libraries (which LGPL code was used, btw?). It's just that packaging and shipping a relinkable binary was way, way down the priority list and they probably just never got around to it.
But for a big corporation with an established IP policy, that's a big no-no.
That's exactly right. I was part of a similar audit at a past company during their exit. We essentially had to inventory the license of every Rails plugin, script, etc. we had ever used.
But for a big corporation with an established IP policy, that's a big no-no.