Enterprise Reporting
Enterprise Reporting
Enterprise Reporting (known as Data Insights until release 191) is your one-stop access to understand your organization's open-source consumption patterns including AI/ML components, risk and remediation patterns, and factors affecting the overall security posture. It summarizes how Sonatype Lifecycle impacts the security profile of the development pipelines within your organization.
Note
We have implemented the dashboards using the Looker™ platform for versatility. The visualizations will continue to evolve in functionality or scope, based on future improvements and user feedback.
Data Handling Processes for Enterprise Reporting
To address the concerns due to data processing with our third-party reporting tool, Looker™, we have implemented a 4-way protection methodology:
Data Storage
No data is stored in any third-party tool. We use the third-party tooling's streaming capability to receive the query results directly from the Sonatype environment in a dedicated instance. The data is transmitted without being stored.Data Anonymization
The information for these visualizations and reports is restricted for an organization from the anonymized telemetry during application analysis performed via Sonatype Data Services.Data Authentication and Authorization
To ensure that the data in these visualizations is accessible to authorized users only, the system programmatically creates obfuscated, unique one-way hash identifiers for the user and the organization's instance.Data Encryption
We implement encryption for data in flight from the Lifecycle environment to the third-party reporting tool.
For added security, the vulnerability data for a specific application or component is not included in any of the dashboards.
Advanced Reporting
To provide deeper reporting clarity, additional data is made available to be used for reporting following all encryption and data handling standards. The data element included in Advanced Reporting is:
- Application Name
When Advanced Reporting is disabled, application names are obfuscated in Enterprise Reporting.
To show application names in Enterprise Reporting, set ADVANCED_REPORTING_INSIGHTS_ENABLED to true using the Configuration REST API. See Enable Advanced Reporting Insights.
Flow for Data Request
- A user invokes a dashboard from the Data Insights feature in Sonatype Lifecycle.
- The browser requests a one-time, unique URL for the insight via an internal IQ Server API.
- The IQ Server invokes the Sonatype Data System API to check for a valid license and account using the standard one-way hash algorithms within IQ Server.
- The Sonatype Data System invokes the Looker™ API to generate the one-time use URL.
- Looker™ returns the fully signed and fully formed URL.
- The Browser renders the URL in the frame in Sonatype Lifecycle.
- Looker™ streams data encrypted from the back-end data systems (Databricks™) to render the report.
Prerequisites
- Your browser has no restrictions on accessing “*. looker.com” URLs
- For the Safari browser, “Prevent cross-site tracking“ in the Settings menu → Privacy is disabled.
Accessing
Click on Enterprise Reporting from the left navigation bar.
Get to know your Enterprise Reporting Landing Page
The Enterprise Reporting landing page displays the following information:
- Rapid Response Reports
Rapid Response Reports provide fast, targeted insights into critical security issues that require immediate attention. These reports are designed to help organizations quickly assess exposure to high-impact vulnerabilities and take timely remediation actions across affected applications and components. - Enterprise Dashboards
Enterprise dashboards offer a set of logically related visualizations or charts to provide a complete picture of key aspects that impact the organization security and compliance risks. The individual visualizations in an enterprise dashboard are curated and compiled to empower users to make data-driven informed decisions and maximize on the capabilities value delivered by using Sonatype Lifecycle to improve the program efficacy. - Data Insights
Data Insights are standalone visualizations that enable focused analytics and data exploration. Based on the data generated as a result of using Sonatype Lifecycle, these visualizations answer specific task-oriented questions like reporting applications containing End-of-Life (EOL) components or AI/ML components, applications on-boarding rate, scan rates, component upgrades (Upgrade Posture) etc. - Partner Solutions
Partner Solutions are partner-provided dashboards and integrations that extend Enterprise Reporting with specialized capabilities from trusted technology partners, such as End-of-Life (EOL) tracking or partner-sourced upgrade recommendations.
Exporting dashboards and table data
Enterprise Reporting dashboards include two action menus: Dashboard actions and Tile actions.
- Dashboard actions are available from the three-dot menu in the top-right corner of the dashboard. Use dashboard actions to refresh dashboard data, show or hide filters, download the dashboard, schedule delivery, or reset filters.
- Tile actions are available from the three-dot menu on an individual visualization or table. Use tile actions to download data for a specific tile or table.
To export the full dataset for a table, open the tile actions menu, select Download data, expand Advanced data options, and set Number of rows and columns to include to All results.
On supported tiles, you can also use the Alerts icon to create alerts based on configured conditions, recipients, frequency, and delivery method.
Rapid Response Reports: React2Shell Impact Report
Explore applications and components impacted by critical React Server Component vulnerabilities using this rapid response report.
Learn more about React2Shell Impact Report
Rapid Response Reports: Mythos Readiness
Cross-reference your open source inventory with Mythos vulnerability data in a single exportable view.
Learn more about Mythos Readiness
Enterprise Dashboard: Success Metrics
Explore your policy violation and remediation patterns using this foundational dashboard.
Learn more about Success Metrics
Enterprise Dashboard: Success Metrics: Remediation Ops
Investigate policy violations and remediation activity across your applications and components with this foundational dashboard.
Learn more about Success Metrics: Remediation Ops
Enterprise Dashboard: Success Metrics: Program Health
Explore your organization’s security posture, remediation efficiency, and policy violation trends with this foundational dashboard.
Learn more about Success Metrics: Program Health
Enterprise Dashboard: Security Risk Trends
Explore your security risk trends and mitigate risk with this foundational dashboard.
Learn more about Security Risk Trends
Enterprise Dashboard: Security Risk Breakdown
Dive deeper into security risk and violation data with this foundational dashboard.
Learn more about Security Risk Breakdown
Enterprise Dashboard: Waivers Explorer
Dive deeper into security risk and violation data with this foundational dashboard.
Learn more about Waivers Explorer
Enterprise Dashboard: Legal Risk Trends
Explore your legal risk trends and mitigate risk with this foundational dashboard.
Learn more about Legal Risk Trends
Enterprise Dashboard: Golden Fixes
Dive deeper into golden fixes and violation data with this foundational dashboard.
Learn more about Golden Fixes
Enterprise Dashboard: Best Practices
Explore your organization’s adoption of best practices and integration coverage across applications over time.
Learn more about Best Practices
Data Insight: AI Models
Explore and inspect the metadata for the open-source AI models used in your applications.
Learn more about AI Models Usage
Data Insight: AI Machine Learning
Observe the consumption of open-source AI/ML components in your applications.
Learn more about ML/AI Apps: Using Machine Learning.
Data Insight: Component EOL
See which components have the status of End of Life (EOL).
Learn more about Component EOL: Retiring Old Code
Data Insight: Supply Chain Monitoring
Review the health of your OSS supply chain and observe key influencing factors.
Learn more about Supply Chain Monitoring
Data Insight: Stack Divergence
Compare your applications' component usage against industry norms to evaluate areas where you've fallen behind the adoption curve
Learn more about Stack Divergence
Partner Solutions: HeroDevs EOL Components
Explore your end-of-life component posture and view partner-provided upgrade recommendations with this partner dashboard.
Learn more about HeroDevs End of Life Components