InnerSource Best Practices

InnerSource Best Practices

Introduction

InnerSource Insight is a feature in Sonatype Lifecycle that identifies proprietary components in your scan results. This tells you when risk in your application is coming from other internal components, saving you time tracking down vulnerabilities that another team is responsible for remediating. Without InnerSource Insight, these proprietary components show up as Unknown Components. Researching the associated open-source dependencies can be challenging. Associating transitive risk with proprietary components can take a lot of time with little reduction in your applications' risk.

Configure your scans so that you see InnerSource identified in your results

Configure your application scans to identify InnerSource Components

Include a CycloneDX Software Bill of Materials (SBOM) with identifying information for all projects

Follow normal waiver practices with Innersource

Follow your normal waiver practices with InnerSource Components

Use bulk waivers to remediate dependencies introduced through Innersource components