Firewall Dashboard

Firewall Dashboard

The Firewall dashboard displays a summary of Firewall operations, components and containers in quarantine and waived. These results are sorted by the most recently quarantined component and can be filtered using the summary metrics.

Summary Metrics

This display lists the number of components monitored in quarantine-enabled repositories.

Metric Description
Supply chain attacks blocked Number of components blocked by Firewall due to malicious-code policy conditions (for example, security-malicious). The count is aggregated per day.
Namespace attacks blocked Number of components blocked due to namespace-conflict policy conditions (for example, namespace-conflict or proprietary name conflict). The count is aggregated per day.
Components quarantined Number of components placed into quarantine after violating repository policies. The metric reflects components quarantined over the last 12 months.
Components auto-released Number of quarantined components automatically released after policy violations were resolved. Calculated from auto-release events over the last 12 months.
Safe components auto-selected Number of requests where Firewall found a policy-compliant version and automatically selected that safe version for the component.
Components waived Number of policy waivers created for repository components. The metric is grouped by waiver creation date over the last 12 months.

Quarantined Components

The Components tab displays components that are currently quarantined across Firewall-enabled repositories.

Navigate the results using the filters or pagination controls. The list can be sorted by the Quarantine Time, Threat Level, and Component.

Selecting the Quarantine Time, Policy, Component, or Repository columns header changes the sort order of the component list.

Metric Description
#### Threat The threat level of the highest policy violation
#### Policy Name Policy name of the highest policy violation. Filter the list by selecting the relevant policies.
#### Quarantine Time The timestamp the component was quarantined. Filter the component list by the past 24 hours, 7 days, 30 days, 90 days, and 12 months.
#### Component The quarantined components. The filter may include any part of the component identifier in the below format. Include the spaces and colon when including more than one property.
[namespace] : [project] : [version]  
``` |
| #### Repository                 | The proxy repository the component was quarantined from. Use the filter by the repository name. The repository link navigates to the repository report view. |

Selecting a table row displays the Component Information Panel for that component.

## Quarantined Containers

The Containers tab displays containers that are currently quarantined across Firewall-enabled repositories.

| Metric                          | Description |
|---------------------------------|-------------|
| Threat                          | The threat level of the highest policy violation |
| Policy Name                     | Policy name of the highest policy violation. |
| Evaluation Time                 | The timestamp when the container starts the evaluation process in Sonatype IQ. |
| Container                       | The quarantined containers. |
| Repository                      | The proxy repository the container was quarantined from. The repository link navigates to the repository report view. |

Selecting a table row displays the Container Information Panel for that container.

## Access Requirements

- The Firewall Dashboard now supports scoped access, users only see data for repositories they have permission on.
  
- Users with `View IQ elements` permission at Repository Manager or Root Organization level see the full dashboard.
  
- Users with permission on specific repositories only see a limited view quarantined components and waivers are filtered to their permitted repositories only.
  
- The Quarantine, Waivers, and Container Images tabs all respect this scoping.
  
- Admins see all data under quarantine and waivers.

Users without this access see the following message:

## Search results

No results found.