Enterprise Reporting

Enterprise Reporting

Enterprise Reporting (known as Data Insights until release 191) is your one-stop access to understand your organization's open-source consumption patterns including AI/ML components, risk and remediation patterns, and factors affecting the overall security posture. It summarizes how Sonatype Lifecycle impacts the security profile of the development pipelines within your organization.

Note
We have implemented the dashboards using the Looker™ platform for versatility. The visualizations will continue to evolve in functionality or scope, based on future improvements and user feedback.

Data Handling Processes for Enterprise Reporting

To address the concerns due to data processing with our third-party reporting tool, Looker™, we have implemented a 4-way protection methodology:

  1. Data Storage
    No data is stored in any third-party tool. We use the third-party tooling's streaming capability to receive the query results directly from the Sonatype environment in a dedicated instance. The data is transmitted without being stored.

  2. Data Anonymization
    The information for these visualizations and reports is restricted for an organization from the anonymized telemetry during application analysis performed via Sonatype Data Services.

  3. Data Authentication and Authorization
    To ensure that the data in these visualizations is accessible to authorized users only, the system programmatically creates obfuscated, unique one-way hash identifiers for the user and the organization's instance.

  4. Data Encryption
    We implement encryption for data in flight from the Lifecycle environment to the third-party reporting tool.

For added security, the vulnerability data for a specific application or component is not included in any of the dashboards.

Advanced Reporting

To provide deeper reporting clarity, additional data is made available to be used for reporting following all encryption and data handling standards. The data element included in Advanced Reporting is:

When Advanced Reporting is disabled, application names are obfuscated in Enterprise Reporting.

To show application names in Enterprise Reporting, set ADVANCED_REPORTING_INSIGHTS_ENABLED to true using the Configuration REST API. See Enable Advanced Reporting Insights.

Flow for Data Request

  1. A user invokes a dashboard from the Data Insights feature in Sonatype Lifecycle.
  2. The browser requests a one-time, unique URL for the insight via an internal IQ Server API.
  3. The IQ Server invokes the Sonatype Data System API to check for a valid license and account using the standard one-way hash algorithms within IQ Server.
  4. The Sonatype Data System invokes the Looker™ API to generate the one-time use URL.
  5. Looker™ returns the fully signed and fully formed URL.
  6. The Browser renders the URL in the frame in Sonatype Lifecycle.
  7. Looker™ streams data encrypted from the back-end data systems (Databricks™) to render the report.

Prerequisites

Accessing

Click on Enterprise Reporting from the left navigation bar.

Get to know your Enterprise Reporting Landing Page

The Enterprise Reporting landing page displays the following information:

Exporting dashboards and table data

Enterprise Reporting dashboards include two action menus: Dashboard actions and Tile actions.

To export the full dataset for a table, open the tile actions menu, select Download data, expand Advanced data options, and set Number of rows and columns to include to All results.

On supported tiles, you can also use the Alerts icon to create alerts based on configured conditions, recipients, frequency, and delivery method.

Rapid Response Reports: React2Shell Impact Report

Explore applications and components impacted by critical React Server Component vulnerabilities using this rapid response report.
Learn more about React2Shell Impact Report

Rapid Response Reports: Mythos Readiness

Cross-reference your open source inventory with Mythos vulnerability data in a single exportable view.
Learn more about Mythos Readiness

Enterprise Dashboard: Success Metrics

Explore your policy violation and remediation patterns using this foundational dashboard.
Learn more about Success Metrics

Enterprise Dashboard: Success Metrics: Remediation Ops

Investigate policy violations and remediation activity across your applications and components with this foundational dashboard.
Learn more about Success Metrics: Remediation Ops

Enterprise Dashboard: Success Metrics: Program Health

Explore your organization’s security posture, remediation efficiency, and policy violation trends with this foundational dashboard.
Learn more about Success Metrics: Program Health

Enterprise Dashboard: Security Risk Trends

Explore your security risk trends and mitigate risk with this foundational dashboard.
Learn more about Security Risk Trends

Enterprise Dashboard: Security Risk Breakdown

Dive deeper into security risk and violation data with this foundational dashboard.
Learn more about Security Risk Breakdown

Enterprise Dashboard: Waivers Explorer

Dive deeper into security risk and violation data with this foundational dashboard.
Learn more about Waivers Explorer

Enterprise Dashboard: Legal Risk Trends

Explore your legal risk trends and mitigate risk with this foundational dashboard.
Learn more about Legal Risk Trends

Enterprise Dashboard: Golden Fixes

Dive deeper into golden fixes and violation data with this foundational dashboard.
Learn more about Golden Fixes

Enterprise Dashboard: Best Practices

Explore your organization’s adoption of best practices and integration coverage across applications over time.
Learn more about Best Practices

Data Insight: AI Models

Explore and inspect the metadata for the open-source AI models used in your applications.
Learn more about AI Models Usage

Data Insight: AI Machine Learning

Observe the consumption of open-source AI/ML components in your applications.
Learn more about ML/AI Apps: Using Machine Learning.

Data Insight: Component EOL

See which components have the status of End of Life (EOL).
Learn more about Component EOL: Retiring Old Code

Data Insight: Supply Chain Monitoring

Review the health of your OSS supply chain and observe key influencing factors.
Learn more about Supply Chain Monitoring

Data Insight: Stack Divergence

Compare your applications' component usage against industry norms to evaluate areas where you've fallen behind the adoption curve
Learn more about Stack Divergence

Partner Solutions: HeroDevs EOL Components

Explore your end-of-life component posture and view partner-provided upgrade recommendations with this partner dashboard.
Learn more about HeroDevs End of Life Components