Developer Dashboard
Developer Dashboard
Sonatype Developer Dashboard provides insights into the extent of application adoption, risk remediation timelines, and the current state of application evaluations.
Note
IDE integration usage is shown in the Sync with IDEs section as a count of distinct users who performed at least one IDE policy evaluation in the last 3 months.
Use the Solution Switcher to open Sonatype Developer. The default landing page is the Dashboard view.
Overview
Adoption Profile
The adoption profile indicates the percentage of applications in your organization that use the Sonatype integration plug-ins for SCM and CI/CD each month.
The trend line can help decide whether the use of Sonatype integration plug-ins should be ramped up, to maintain the security posture.
Risk and Remediation
The Count (y-axis) represents the number of active waivers and the number of applications with failing violations.
The trend lines can help determine the corrective actions needed to remediate the risks.
Mean Time to Remediate
The Mean Time to Remediate represents the average age of the violations that were remediated each month in your applications.
The trend line gives an insight into the priority given to remediation tasks on a monthly basis.
Build Stage Risk Monitoring Summary
This section summarizes the risks to your build pipeline and displays the IQ Server scan findings for each application. It contains:
- Applications that are currently configured or not configured with CI/CD plugins. Click on the Configure button to find out more about configuration details.
- Applications that have or do not have automated source control feedback enabled. Click on the Configure button to find out more about configuration details.
- The date of the last commit.
- The date of the last evaluation.
- The Priorities column provides a View link to open the priorities report for the selected application.
Using the Filter
Use the filter to limit the scope of your focus to target applications that are configured/non-configured for CI/CD or SCM feedback.
Using the Search
To navigate to a specific application, enter the name of the application in the Search box at the top of the applications list.
Review the Application Configuration
Click on an application name to view the existing IQ Server settings for the application, including the assigned application categories, policies applied, enabled/disabled legacy violations, continuous monitoring settings, proprietary component configuration, component labels assigned, applicable license threat groups, existing source control integration, InnerSource repository configuration, and user roles and access.
Integration Summary Cards
The bottom section of the dashboard displays integration summary cards for CI/CD, SCM, and IDE integrations.
- Sync CI With Sonatype Developer – Displays information about CI/CD integrations used for binary scanning and policy evaluation during pipeline execution.
- Sync with SCM – Displays information about source control integrations used for automated source control feedback and policy monitoring.
- Sync with IDEs – Displays the count of distinct IQ users who have run an IDE scan or a v2 third-party/SBOM scan in the last 3 months.
Use the Solution Switcher
Need to switch to another Sonatype solution, seamlessly?
Click on the Solution Switcher icon in the top right navigation bar to experience other licensed Sonatype solutions, including Sonatype Lifecycle, Sonatype Developer, Sonatype SBOM Manager, and Sonatype Repository Firewall.