Golden Fixes Dashboard
Golden Fixes Dashboard
About the Data
Data Refresh Frequency: Updated daily at around 12:50 UTC. New fix activity can take up to 24 hours to appear.
Displays Data for: All open violations (regardless of the date they were opened) and resolved violations on or after January 1, 2024. For new installations, data will be visible within a week after the first scan.
To view historical data (generated before January 1, 2024) version 188 or higher is required.
Minimum Requirements: Applications must be scanned at least once, after upgrade to version 184. The dashboard currently shows data related to violations and remediations that are discovered after upgrade to version 184.
Overview
The Golden Fixes Dashboard helps you discover the potential impact of adopting golden fixes across your organization. Golden Fixes are validated, policy-aligned pull requests that automatically remediate open violations. This dashboard highlights how many violations could be resolved with Golden Fixes and helps you identify where they can have the greatest impact across your organization.
By providing clear visibility into security improvements that can be achieved with minimal effort, the dashboard enables you to view how many open policy violations could be remediated through golden pull requests. This gives executives, security teams, and development teams actionable insights into low-effort fixes that can significantly improve their security posture.
Use filters like date range, application, threat level, component type, component name and more to focus your view and identify the most impactful opportunities for remediation.
About Golden Fixes
Golden Fixes are validated component versions that resolve security violations without introducing breaking changes. When a component has a golden version available, you will receive the best recommended option to upgrade, which can eliminate vulnerabilities while maintaining application functionality. These fixes are automatically identified by analyzing component direct dependencies and suggesting safe upgrade paths that have been verified as policy-compliant.
Explore Your Golden Fixes Dashboard
Our dynamic dashboard lets you drill into your application’s golden fixes profile with a rich set of filters. Narrow your view by date range, organization, sub orgs, application (and its category), policy threat level, policy name, development stage, component type, vulnerability and component name.
Date Range: Defaults to last 12 months. Adjustable to any custom period.
Organization: Select one or more customer organizations.
Sub Orgs: Select one or more sub orgs beneath the chosen organization. When a parent organization is selected, the sub orgs list is limited to that branch’s descendant organizations.
Application: Choose specific applications or all.
App Category: Filter by business unit or project type.
Policy Threat Level:
- Critical
- Severe
- Moderate
- Low.
Component Type: Ecosystem filters (Maven, npm, NuGet, etc.).
Development Stages
- Build (default)
- Compliance
- Operate
- Proxy
- Release
- Source
- Stage-release
Component Name: Filter results by specific component name to quickly locate relevant upgrade recommendations.
Use these controls to slice and dice your risk data, hone in on trouble spots, and track progress across your teams and projects.
The build stage is selected by default.
Downloading Dashboard and Table Data
You can download dashboard and table data using the dashboard export options.
Saved Filters:
The Enterprise Reporting Sonatype Default filter set is always available and cannot be changed or removed. To adjust filters, save your selections as a new saved filter set. Any saved sets you create can be edited or deleted as needed. Scheduled deliveries that reference a saved set use the values that were saved at the time of scheduling and will not update automatically if the saved set is edited later.
Saved Filters capture a named set of the dashboard’s current filter selections so you can quickly reopen the dashboard scoped to that view. Use the following steps below to create, apply, edit, set a default, delete, and schedule saved filter sets.
Apply the filters you want for the view (date range, Organization, Sub Orgs, Application, Threat Level, Component Name, etc.).
Open Saved Filters and choose Save As to create a named saved set; the UI validates the name as you type.
To update a set, apply it and choose Save to overwrite, or Save As to create a variation. An asterisk in the filter name indicates unsaved changes.
Make any saved set your personal default with Make My Default. Sonatype Default is always available and protected; deleting a personal default reverts to Sonatype Default.
To delete a saved set, select it and confirm. Deletion removes the set from your account only and, if it was your default, resets the default to Sonatype Default.
A saved set stores only filters that exist on the dashboard where it was created. Applying it to another dashboard uses only matching filters; unsupported filters are ignored. Use Save As to preserve every selection across dashboards.
Scheduled exports or deliveries that reference a saved set use the values saved at schedule time; editing the saved set later does not change existing scheduled deliveries.
Note
Filter set names are validated as you type. Filter set name must be 1–35 characters and may not include special characters such as ^, &, %, or <. The UI shows an inline error for invalid characters or length violations and prevents saving until validation passes.
Total Open Violations
This metric displays the total count of open (non-waived) security violations across all applications within your selected filters. This represents your baseline security exposure before applying any golden fixes.
Violations with Golden Fixes Available
This section shows both the count and percentage of open violations that can be resolved using golden fixes. This metric helps you understand what portion of your current security exposure can be addressed through low-effort remediation.
The percentage calculation removes the "A" from the display to show: "Violations with Golden Fixes Available" rather than "Violations with A Golden Fixes Available."
This gives you immediate insight into the potential impact of implementing a golden fixes strategy across your organization.
Violations with Golden Fixes Available by Threat Level
This pie chart breaks down Golden Fix opportunities by policy threat level, showing the following distribution across:
- Critical(threat levels 8-10)
- Severe(threat levels 6-7)
- Moderate(threat levels 3-5)
- Low(threat levels 1-2)
Use this visualization to prioritize your golden fixes adoption strategy, focusing first on critical and severe vulnerabilities that can be resolved with minimal effort. The chart shows both count and percentage for each threat level.
Applications and Components with Golden Fixes Available
Applications with Golden Fixes Available
This table lists applications that contain violations eligible for golden fixes remediation.
For each application, you can see the following :
- Application Name
- Number of Violations that can be resolved with golden fixes.
- Last Scan Date (based on the most recent open violation detected).
Applications that have been scanned but contain no violations will not appear in this table, as there are no security issues requiring remediation.
Golden Fixes Available for Components
This detailed table shows the specific golden fixes options available for your components. Each row represents a golden version recommendation for a unique component.
Note
The dashboard now displays only one golden recommendation per component, representing the best verified and policy-compliant upgrade path.
This table includes:
- Component Name and Current Version
- Golden Version (recommended upgrade target)
- Number of Applications using this component
- Violation Count that would be resolved
Realized Success
Note
The Realized Success section requires Sonatype Lifecycle version 197 or higher. If you are using an earlier version, the section may appear blank or partially populated until you upgrade to the required version.
The Realized Success section provides visibility into the actual adoption and outcomes achieved using Golden Fixes. While the earlier part of the dashboard (Projected Outcomes) focuses on potential improvements that could be realized through Golden Fixes, this new section reflects the real-world results.
The upper charts and tables in the Projected Outcome section continue to reflect open violations, while Realized Success displays data for breaches that have already been fixed. Waived violations are excluded from all calculations.
The data in Realized Success is divided into two main categories:
- With Golden Fixes:
Represents violations that were automatically remediated through Golden Pull Requests generated by Lifecycle. These are validated, policy-compliant upgrade paths that have been successfully applied to resolve violations.
- Without Golden Fixes:
Represents violations that were fixed manually or through other means, such as removing or upgrading components outside of the Golden Fix process.
By comparing these two groups, the dashboard helps users understand the effectiveness of automated Golden Fixes relative to manual remediation.
The Realized Success charts display comparative metrics such as Mean Time to Remediate (MTTR) for each remediation type. In general, violations resolved through Golden Fixes are expected to have a lower MTTR, reflecting faster remediation and greater efficiency achieved through automation.
The visualizations and data in this section help answer key questions such as:
- How many violations have been successfully resolved using Golden Fixes.
- How does the remediation time for automated fixes compare to manual fixes.
- What proportion of overall remediated violations are attributed to Golden Fixes.
Cross-filtering works consistently with other sections of the dashboard, though datasets for open and remediated violations do not overlap. Filters applied at the top of the dashboard (such as date range, application, threat level, or component type) also apply to the Realized Success section.