Advanced Search

Advanced Search

Advanced Search helps you find configuration and component details through the Lifecycle, Developer, or SBOM Manager UI.

The Advanced Search does not provide results for Repository Firewall components. Use the Firewall Dashboard to search for quarantined components.

See Firewall Dashboard

To script searches for Repository Firewall, use Firewall REST API.

The Advanced Search does not return policy violations. Use the Lifecycle Dashboard to search policy violations.

See Lifecycle Dashboard

To script advanced searches for Lifecycle, use Advanced Search REST API.

Advanced Search is enabled by default, and the search index is created automatically. However, System Administrators can manually re-create the index from the System Preferences menu. To do so, complete the following steps:

  1. Select the_System Preferences_ icon (gear icon) from the top-navigation menu.
  2. Select Advanced Search from the drop-down list.
  3. Ensure that the _Enabled_checkbox in the Advanced Search Status field remains checked.
  4. Select the Re-Index button to trigger the re-index operation.

The Last Indexed date and timestamp will update when re-indexing is complete.

Performing a Search

Advanced Search lets you build precise queries by combining multiple search terms with the supported syntax. Use Query Builder for guided rules or type directly in the search box to find organizations, applications, components, or vulnerabilities by name or ID.

The_Advanced Search_ page has two built-in ways to construct queries:

Query Builder

Query Builder guides you to add rules to build a query. You can add multiple rules through Add Search Item and join them with AND or OR logical operators. Each rule has the following fields:

To build a query using Query Builder, take the following steps:

  1. Select Use Query Builder to access the Build Query Rules screen.
  2. Select the required attribute from the _Field_dropdown list (for example, Organization Name, Application Name, Application Category ID, Component Hash).
  3. Select either_Partial Match_ or Exact Match from the Match Type dropdown list. The Partial Match option wraps multi-word values in quotes and appends a wildcard.

Example: typing testbecomes organizationName:"test"* in the search box.

  1. If you wish to add another rule, select Add Search Item and repeat steps 2-3.

  2. Join the rules using AND or OR logical operator.

  3. Select _Search_to perform the search.

  4. Review results and use Previous or _Next_to move between the pages.

Note

Craft Your Search Terms For The Best Results

Use these tips when you write queries for Advanced Search. The Query Builder and the Add Search Terms buttons help if you prefer a guided workflow. The examples below show common queries and explain useful operators and patterns.

Examples

Find a specific vulnerability by its ID.

CVE-2019-7619

Search for vulnerabilities that start with a specific value. The asterisk (*) matches any number of characters.

CVE-2019-*

Search by application name. Use * as a wildcard for partial matches.

applicationName:nexus*

Search by application name and restrict results to application documents.

applicationName:nexus* AND itemType:APPLICATION

Search by application name and restrict results to security vulnerabilities.

applicationName:nexus* AND itemType:SECURITY_VULNERABILITY

Search by application name for open security vulnerabilities.

applicationName:Nexus* AND vulnerabilityStatus:Open

Note

You do not need itemType:SECURITY_VULNERABILITY when you use vulnerabilityStatus:Open The vulnerabilityStatus field already returns items of type SECURITY_VULNERABILITY.

Search specific components with a specific vulnerability state.

itemType:SECURITY_VULNERABILITY AND componentFormat:(a-name OR npm) AND vulnerabilityStatus:(Acknowledged OR "Not Applicable")

This alternative is equivalent to the example above. It shows that OR is optional. In this syntax the default operator between items in a parenthesis is OR.

componentFormat:(a-name npm) AND vulnerabilityStatus:(Acknowledged "Not Applicable")

Tip

Both queries above are equivalent, they return the same result. It is a good example of not actually requiring the itemType. OR is the default operator so it can be omitted.

Important

Also watchout for special characters that need escaping e.g.() and "".

Add Search Terms

Selecting the_Add Search Terms_ option opens a list of pre-formatted search query options (e.g., applicationId for searching on application ID, applicationName for searching on application name, etc.). Selecting a term inserts it as a properly formatted query field within the main Search box.

To use the Add Search Terms option, take the following steps:

  1. Select Add Search Terms.

  2. Select your desired search terms (e.g., organizationId, applicationId, etc.) from the list of options.

  3. Properly formatted field tokens appear in the Search box as you select your desired terms. Enter values for each term after the colon to complete it.

  4. A list of results displays under your query.

Automatic Re-indexing

The Advanced Search automatically re-indexes when changes are made to the data. Automatic indexing only applies to data changes made while the feature is enabled.

Search Performance

Advanced Search retrieves results from large data sets. To limit risk to server performance, it enforces limits to the query results. You will see an error message asking you to narrow your search with additional filters.

Exporting Advanced Search Results

You may export search results by selecting the_Export Results_ button from the _Advanced Search_page. The search results are downloaded in a CSV file.

You can also export search results with the Advanced Search REST API.

Advanced Search Limitations

The Advance Search does not list all vulnerabilities known to Sonatype. The complete list of vulnerabilities are stored in Sonatype's proprietary data and is used during application analysis.

Reference- search item types and field names

Refer to the tables below for search item types and examples when building a search query.

Table 4. ORGANIZATION

Field Name Example
organizationId organizationId:ROOT_ORGANIZATION_ID
organizationName organizationName:"Root Organization"

Table 5. APPLICATION

Field Name Example
applicationId applicationId:22951997a36045ab8593e3b6aafb9745
applicationName applicationName:"My Application Name"
applicationPublicId applicationPublicId:MyApplicationPublicId
applicationVersion applicationVersion:1.0
sbomSpecifications sbomSpecifications:CycloneDx

Table 6. APPLICATION_CATEGORY

Field Name Example
applicationCategoryId applicationCategoryId:319cde35ef9749f4ab99a6473ad10b74
applicationCategoryName applicationCategoryName:Distributed
applicationCategoryColor applicationCategoryColor:yellow
applicationCategoryDescription applicationCategoryDescription:"outside the company"

Table 7. COMPONENT

Field Name Example
componentHash componentHash:f5149f0aaf01daf4bb2f
componentFormat componentFormat:maven
componentName componentName:"javax.mail : mailapi : 1.4.2"
componentCoordinateGroupId componentCoordinateGroupId:commons-fileupload
componentCoordinateArtifactId componentCoordinateArtifactId:mailapi
componentCoordinateVersion componentCoordinateVersion:1.2.16
componentCoordinateClassifier componentCoordinateClassifier:dist
componentCoordinateExtension componentCoordinateExtension:jar
componentCoordinateName componentCoordinateName:"org.webjars bootstrap"
componentCoordinateQualifier componentCoordinateQualifier:cp37-cp37m-win32
componentCoordinatePackageId componentCoordinatePackageId:loadash
componentCoordinateArchitecture componentCoordinateArchitecture:x86_64
componentCoordinatePlatform componentCoordinatePlatform:ruby

Table 8. COMPONENT_LABEL

Field Name Example
componentLabelId componentLabelId:0d3f4015332e4b298ac1ed95c12ff3a3
componentLabelName componentLabelName:Architecture-Cleanup
componentLabelColor componentLabelColor:orange
componentLabelDescription componentLabelDescription:"relics of a build"

Table 9. POLICY

Field Name Example
policyId policyId:b4ca64a8b8264f03b65127016859b2a2
policyName policyName:Component-Unknown
policyThreatCategory policyThreatCategory:security
policyThreatLevel policyThreatLevel:10

Table 10. SECURITY_VULNERABILITY

Field Name Example
reportId reportId:a6860277aa844ab5af8bfef041f7e6e5
policyEvaluationStage policyEvaluationStage:Build
vulnerabilityId vulnerabilityId:CVE-2014-3625
vulnerabilityStatus vulnerabilityStatus:Open
vulnerabilitySeverity vulnerabilitySeverity:7.1
vulnerabilityDescription vulnerabilityDescription:"directory traversal"

Table 11. POLICY_VIOLATION

Field Name Example
policyViolationPolicyName policyViolationPolicyName:Security-High
policyViolationPolicyId policyViolationPolicyId:12345
policyViolationThreatCategory policyViolationThreatCategory:Security
policyViolationThreatLevel policyViolationThreatLevel:[7 TO 10]
policyViolationWaiverStatus policyViolationWaiverStatus:Active
policyViolationConstraintName policyViolationConstraintName:"License Threat Group"

Table 12. LICENSE

Field Name Example
componentEffectiveLicenseId componentEffectiveLicenseId:Apache-2.0
componentEffectiveLicenseName componentEffectiveLicenseName:"Apache License 2.0"
componentLicenseThreatGroupName componentLicenseThreatGroupName:Copyleft
componentLicenseThreatLevel componentLicenseThreatLevel:[7 TO 10]

Search results

No results found