Update Your IQ Server License Threat Groups - Sonatype Labs - Sonatype Community

Update Your IQ Server License Threat Groups

The license threat group updater will apply the latest Sonatype provided license classification to your running IQ server’s license threat groups. This will alleviate any “License Threat Group not Assigned” policy violations, in addition to keeping your license catalog up to date.

Updating Nexus IQ License Threat Groups

Please consider backing up your existing installation prior to running the updater. For instructions: Backup the IQ Server

usage: java -jar ltg-updater-1.0.0.jar -s http://localhost:8070 -u adminUser -p adminPassword -i path/to/update.csv -d -f [-d] [-e] [-f] [-h] [-i <arg>] [-p <arg>] [-s <arg>] [-u <arg>]
 -d,--default          Select all default choices.
 -e,--silent           Disable all input and output to the CLI.
                       Automatically selects default choices.
 -f,--force_review     Even if default choices or silent are selected this
                       option will force the review of license changes.
 -h,--help             Prints help message.
 -i,--input <arg>      Path to CSV file of license to LTG mapping.
 -p,--password <arg>   Admin password.
 -s,--server <arg>     Url to Nexus IQ server.
 -u,--user <arg>       Admin username.

The updater currently only supports basic auth and must be supplied credentials for the Nexus IQ Admin user as it will make updates to the Root Organization LTGs. It is recommended that users enable the -d and -f options to select both default choices and to force a review of any license LTG changes.

java -jar ltg-updater-1.0.0.jar -s http://localhost:8070 -u admin -p admin123 -i license_ltgs_12052019.csv -d -f

Prompts

Add all unassigned licenses to LTGs in root organization? [Y/n]

This is asking if all currently unassigned licenses to should be assigned to LTGs in the Root Organization. Recommended answering ‘Yes’. This will also recreate any Sonatype defined LTGs that have been removed from the Root Organization for any reason.

License 'SautinSoft-Document-.Net-LA' is now assigned to LTG 'Banned', but that LTG does not exist in organization 'Sandbox Organization', would you like to create a new LTG for this organization that represents the 'Banned' LTG? [y/N]

If you are very particular about licenses, or have created an ‘approved LTG’, it may be best to not create this new LTG.

License Updates

If you responded that you wish to create a new LTG, you will be prompted for a new LTG name and threat level. After this LTG is created all future licenses in this update that would map to the Sonatype suggested LTG will instead map to your custom LTG for that organization.

Updating 'SautinSoft-Document-.Net-LA':
    'Internal Organization' : 'My Approved Licenses' -> 'My Approved Licenses'
    'Sandbox Organization' : 'My Restricted Licenses' -> '2019-09_license_update Banned'

The above update statement highlights that all licenses that Sonatype is assigning to ‘Banned’ will instead be mapped to ‘2019-09_license_update Banned’ for the organization ‘Sandbox Organization’.

Review LTG updates? [Y/n] y

New licenses added to Root Organization:

Banned
        MS-Report-Viewer-Runtime-for-MS-SQL-Server
        MS-SCLR-For-Sql-Server-2016
        MS-VS-2015-Pre-Release-Software-License
        SautinSoft-Document-.Net-LA
        SautinSoft-Excel-to-PDF-.Net-LA
        SautinSoft-HTML-to-RTF-.Net-LA
        SautinSoft-PDF-Focus-.Net-LA
        SautinSoft-PDF-Metamorphosis-.Net-LA
        SautinSoft-PDF-Vision-.Net-LA

Commercial
        MS-SQL-Server-2017-SMO-License
        MS-VS-2015-SDK-License

Requirements

Download

ltg-updater-1.0.3.jar (8.4 MB)

license_threat_groups_02282025.csv (87.1 KB)

Help

For questions or help reply to this thread. Please do not submit company confidential information.