Getting Started with Sonatype Guide
Getting Started with Sonatype Guide
Getting started with Sonatype Guide is simple. You can begin exploring Guide with or without signing in, depending on how deeply you want to research open-source components and vulnerabilities.
If you’re just getting started, you can use Guide anonymously to search for components and publicly disclosed vulnerabilities. This allows you to quickly explore open-source intelligence and decide when you’re ready to sign up.
When you’re ready to unlock deeper insights and additional capabilities, you can sign up for a free account. Once you’ve registered with Sonatype, you will be invited to sign up for Guide with either your Google or GitHub account.
Using Sonatype Guide Without Signing In
You can start using Sonatype Guide immediately without creating an account.
As an anonymous user, you can:
- Search for open-source components.
- Search for publicly disclosed vulnerabilities (such as CVEs)
- Browse component and vulnerability results
- Review basic details such as ecosystem, latest version, licenses, and severity
Anonymous access is ideal for quick research and initial exploration. When you reach features or insights that required an account, Guide will prompt you to sign up.
See Anonymous Access to Sonatype Guide for details on available features and usage limits.
Signing Up for Guide
Signing up for Guide takes only seconds.
Guide allows you to sign up with either your existing GitHub or Google account. Select your desired option in the sign-in window.
Once you've signed up, you'll be redirected to the Guide home screen.
From here, you can jump right in to researching, automating, and integrating with Sonatype Guide.
Understanding Policy
Managing acceptable risk through policies allows Guide to provide scannable “Meets Policy” checkpoints in a number of different areas across the application.
You can see the policies your Guide instance is using by selecting the Policy option under Settings from the main navigation menu.
Note
Note that the policies Guide uses are not editable at this time.
Sonatype Guide comes with three built-in policies:
- No Malware – This policy prevents any dependency containing malware (i.e., malicious open-source components) from passing a policy check.
- No CVSS 7.0+ – Any component version with a CVSS score of 7.0 or higher (High or Critical) will fail policy checks.
- No Copyleft Licenses – Packages under copyleft license families will fail policy checks. These licenses impose redistribution obligations that can cause conflict with commercial use.
Components that fail policy still remain searchable for transparency. However, to allow you to quickly exclude certain components at a glance, policy compliance is displayed in a few locations throughout Guide:
- The Policy Compliance section of a component page
- The Meets Policy column in version tables
- The Meets Policy field in search results
Search results
No results found.