Golden Fixes Dashboard

Golden Fixes Dashboard

About the Data

Data Refresh Frequency: Updated daily at around 12:50 UTC. New fix activity can take up to 24 hours to appear.

Displays Data for: All open violations (regardless of the date they were opened) and resolved violations on or after January 1, 2024. For new installations, data will be visible within a week after the first scan.

To view historical data (generated before January 1, 2024) version 188 or higher is required.

Minimum Requirements: Applications must be scanned at least once, after upgrade to version 184. The dashboard currently shows data related to violations and remediations that are discovered after upgrade to version 184.

Overview

The Golden Fixes Dashboard helps you discover the potential impact of adopting golden fixes across your organization. Golden Fixes are validated, policy-aligned pull requests that automatically remediate open violations. This dashboard highlights how many violations could be resolved with Golden Fixes and helps you identify where they can have the greatest impact across your organization.

By providing clear visibility into security improvements that can be achieved with minimal effort, the dashboard enables you to view how many open policy violations could be remediated through golden pull requests. This gives executives, security teams, and development teams actionable insights into low-effort fixes that can significantly improve their security posture.

Use filters like date range, application, threat level, component type, component name and more to focus your view and identify the most impactful opportunities for remediation.

About Golden Fixes

Golden Fixes are validated component versions that resolve security violations without introducing breaking changes. When a component has a golden version available, you will receive the best recommended option to upgrade, which can eliminate vulnerabilities while maintaining application functionality. These fixes are automatically identified by analyzing component direct dependencies and suggesting safe upgrade paths that have been verified as policy-compliant.

Explore Your Golden Fixes Dashboard

Our dynamic dashboard lets you drill into your application’s golden fixes profile with a rich set of filters. Narrow your view by date range, organization, sub orgs, application (and its category), policy threat level, policy name, development stage, component type, vulnerability and component name.

Date Range: Defaults to last 12 months. Adjustable to any custom period.

Organization: Select one or more customer organizations.

Sub Orgs: Select one or more sub orgs beneath the chosen organization. When a parent organization is selected, the sub orgs list is limited to that branch’s descendant organizations.

Application: Choose specific applications or all.

App Category: Filter by business unit or project type.

Policy Threat Level:

Component Type: Ecosystem filters (Maven, npm, NuGet, etc.).

Development Stages

Component Name: Filter results by specific component name to quickly locate relevant upgrade recommendations.

Use these controls to slice and dice your risk data, hone in on trouble spots, and track progress across your teams and projects.

The build stage is selected by default.

Downloading Dashboard and Table Data

You can download dashboard and table data using the dashboard export options.

Saved Filters:

The Enterprise Reporting Sonatype Default filter set is always available and cannot be changed or removed. To adjust filters, save your selections as a new saved filter set. Any saved sets you create can be edited or deleted as needed. Scheduled deliveries that reference a saved set use the values that were saved at the time of scheduling and will not update automatically if the saved set is edited later.

Saved Filters capture a named set of the dashboard’s current filter selections so you can quickly reopen the dashboard scoped to that view. Use the following steps below to create, apply, edit, set a default, delete, and schedule saved filter sets.

Note

Filter set names are validated as you type. Filter set name must be 1–35 characters and may not include special characters such as ^, &, %, or <. The UI shows an inline error for invalid characters or length violations and prevents saving until validation passes.

Total Open Violations

This metric displays the total count of open (non-waived) security violations across all applications within your selected filters. This represents your baseline security exposure before applying any golden fixes.

Violations with Golden Fixes Available

This section shows both the count and percentage of open violations that can be resolved using golden fixes. This metric helps you understand what portion of your current security exposure can be addressed through low-effort remediation.

The percentage calculation removes the "A" from the display to show: "Violations with Golden Fixes Available" rather than "Violations with A Golden Fixes Available."

This gives you immediate insight into the potential impact of implementing a golden fixes strategy across your organization.

Violations with Golden Fixes Available by Threat Level

This pie chart breaks down Golden Fix opportunities by policy threat level, showing the following distribution across:

Use this visualization to prioritize your golden fixes adoption strategy, focusing first on critical and severe vulnerabilities that can be resolved with minimal effort. The chart shows both count and percentage for each threat level.

Applications and Components with Golden Fixes Available

Applications with Golden Fixes Available

This table lists applications that contain violations eligible for golden fixes remediation.

For each application, you can see the following :

Applications that have been scanned but contain no violations will not appear in this table, as there are no security issues requiring remediation.

Golden Fixes Available for Components

This detailed table shows the specific golden fixes options available for your components. Each row represents a golden version recommendation for a unique component.

Note

The dashboard now displays only one golden recommendation per component, representing the best verified and policy-compliant upgrade path.

This table includes:

Realized Success

Note

The Realized Success section requires Sonatype Lifecycle version 197 or higher. If you are using an earlier version, the section may appear blank or partially populated until you upgrade to the required version.

The Realized Success section provides visibility into the actual adoption and outcomes achieved using Golden Fixes. While the earlier part of the dashboard (Projected Outcomes) focuses on potential improvements that could be realized through Golden Fixes, this new section reflects the real-world results.

The upper charts and tables in the Projected Outcome section continue to reflect open violations, while Realized Success displays data for breaches that have already been fixed. Waived violations are excluded from all calculations.

The data in Realized Success is divided into two main categories:

Represents violations that were automatically remediated through Golden Pull Requests generated by Lifecycle. These are validated, policy-compliant upgrade paths that have been successfully applied to resolve violations.

Represents violations that were fixed manually or through other means, such as removing or upgrading components outside of the Golden Fix process.

By comparing these two groups, the dashboard helps users understand the effectiveness of automated Golden Fixes relative to manual remediation.

The Realized Success charts display comparative metrics such as Mean Time to Remediate (MTTR) for each remediation type. In general, violations resolved through Golden Fixes are expected to have a lower MTTR, reflecting faster remediation and greater efficiency achieved through automation.

The visualizations and data in this section help answer key questions such as:

Cross-filtering works consistently with other sections of the dashboard, though datasets for open and remediated violations do not overlap. Filters applied at the top of the dashboard (such as date range, application, threat level, or component type) also apply to the Realized Success section.