Legal Risk Trends

Legal Risk Trends

About the Data

Data Refresh Frequency: Updated daily at around 14:45 UTC. New violation data can take up to 24 hours to appear.

Displays Data for: All open violations (regardless of the date they were opened) and resolved violations on or after January 1, 2024. For new installations, data will be visible within a week after the first scan.

To view historical data (generated before January 1, 2024) version 188 or higher is required.

Minimum Requirements: Applications must be scanned at least once, after upgrade to version 184. The dashboard currently shows data related to violations and remediations that are discovered after upgrade to version 184.

Overview

The Legal Risk Trends dashboard helps you keep a pulse on how your applications handle open-source legal risks over time. It draws on data gathered by Sonatype Lifecycle as it detects policy violations and tracks remediation activities at every stage of your development pipeline. By charting your team’s Fix Rate and Mean Time to Remediate (MTTR), you’ll quickly see whether you’re meeting your risk-management benchmarks, and where processes might need tightening.

With clear side-by-side views of violation counts and average remediation times, you can judge both the volume and severity of legal exposures in one glance. If your MTTR stays comfortably within your targets, you might choose to adjust _Lifecycle_policies from “Fail” to “Warn,” avoiding unnecessary release blockages while keeping risk under control.

Digging deeper into MTTR trends also uncovers which vulnerabilities are taking the longest to resolve, and which policy threat levels demand your immediate attention. Armed with that insight, you can fine-tune your remediation playbook and ensure your teams focus first on the highest-risk issues lurking in your open-source dependencies.

The Legal Risk Trends dashboard displays the following metrics:

Explore Your Legal Risk Trends Dashboard

Our dynamic dashboard lets you drill into your application’s legal risk profile with a rich set of filters. Narrow your view by date range, organization, sub orgs, application (and its category), policy threat level, development stage, violation type, security policy name, component type, remediation status, or waiver reason.

Violation Types

Remediation Status

Waiver Reasons

Development Stages

Use these controls to slice and dice your risk data, hone in on trouble spots, and track progress across your teams and projects.

The build stage is selected by default.

Note

Example: If a customer says, “I don’t see the release stage in the filter,” it is because none of their scanned applications include release-stage data. The same logic applies to the other filters.

Downloading Dashboard and Table Data

You can download dashboard and table data using the dashboard export options.

For instructions on exporting dashboards, tables, and scheduling deliveries, see Exporting Dashboards and Table Data .

Saved Filters:

The Enterprise Reporting Sonatype Default filter set is always available and cannot be changed or removed. To adjust filters, save your selections as a new saved filter set. Any saved sets you create can be edited or deleted as needed. Scheduled deliveries that reference a saved set use the values that were saved at the time of scheduling and will not update automatically if the saved set is edited later.

Saved Filters capture a named set of the dashboard’s current filter selections so you can quickly reopen the dashboard scoped to that view. Use the following steps below to create, apply, edit, set a default, delete, and schedule saved filter sets.

Note

Filter set names are validated as you type. Filter set name must be 1–35 characters and may not include special characters such as ^, &, %, or >. The UI shows an inline error for invalid characters or length violations and prevents saving until validation passes.

Daily Open Violations - License Threat Group

The Daily Open Violation - License Threat Group chart displays the number of violations that were open on each day, across all applications that match the selected filters.

Open violations are counted based on their status and duration of being open. If a violation is detected and remains unresolved, it continues to count as open for each day it remains unremediated.

This chart does not include violations that are both detected and remediated on the same day.

More Examples:

  1. A violation that was opened on 30/11/2024 and has not been fixed or waived, will count as 1 open violation every day from 30/11/2024 until now.
  2. A violation that was opened on 30/11/2023 and waived/remediated on 30/11/2024, will count as 1 open violation for each day between 30/11/2023 and 30/11/2024.
  3. A violation that was opened and fixed/remediated on the same day (30/11/2023) will not appear in the chart.
  4. A violation that was opened on 30/11/2023, waived on 30/12/2023, and fixed on 30/01/2024, will count as 1 open violation for each day between 30/11/2023 and 30/12/2023.

Daily Open Violation

This chart displays how many legal violations remained open on each day. It helps track the volume and duration of unresolved violations over time. Violations fixed on the same day as they were identified are not included.

More Examples:

  1. A violation that was opened on 30/11/2024 and has not been fixed or waived will count as 1 open violation per day from 30/11/2024 until today.
  2. A violation that was opened on 30/11/2023 and waived/remediated on 30/11/2024 will count as 1 open violation per day between those dates.
  3. A violation that was opened and remediated on the same day (30/11/2023) will not appear in the chart.
  4. A violation that was opened on 30/11/2023, waived on 30/12/2023, and fixed on 30/01/2024 will count as 1 open violation per day between 30/11/2023 and 30/12/2023.

Waived Legal Violations

Displays the number of violations that were waived each month. It includes all waivers, regardless of whether the violation was later fixed or unwaived and is grouped by waiver reason.

Legal Waiver Requests Submitted

This chart displays the number of license policy waiver requests submitted within the selected date range. This metric focuses only on license policy waiver requests.

Legal Violations Over Time

This chart displays month-end snapshots of both open and waived violations. It provides a high-level view of trends in unresolved and waived issues without daily breakdowns.

This chart includes three lines:

Examples:

Note

The chart uses month-end snapshots. Filtering by a mid-month range (e.g., Jan 1–15) will not display data since January's snapshot is taken on Jan 31.

Monthly Legal Violation Activity

Summarizes violation activity on a monthly basis, showing how many were open, waived, or fixed by the end of each month. This is useful for understanding overall resolution trends.

This chart breaks down violation status by month:

Mean Time to Triage

Displays how long it takes on average to waive, fix, or triage a violation. Helps assess response efficiency and track improvement over time based on waived/fixed timelines.

This chart displays the following key metrics to measure response speed:

MTTF (Mean Time to Fix)

Example: 3 violations fixed in July.

If 3 violations were fixed in July, and they took 3, 5, and 7 days to fix, the average time (MTTF) would be 5 days.

MTTT (Mean Time to Triage)

Example: 3 violations triaged in March.

If three violations were opened on March 1. One was waived on March 10th and fixed later (9 days), another was fixed on March 15th without being waived (14 days), and the third was waived on March 15th but not yet fixed (14 days), the Mean Time to Triage (MTTT) would be calculated as (9 + 14 + 14) ÷ 3 = 12 days.

Triage Rate

This chart displays the proportion of open violations that were waived or fixed during each month. This rate helps measure how effectively teams are resolving issues within a given period.

Active Legal Waivers Per Month

Provides a month-end snapshot of active legal waivers, grouped by waiver reason. Helps understand which types of waivers are currently in effect.

This chart shows active waivers at the end of each month (monthly snapshot).

Note

Customer needs to be on IQ version 189 or later to observe any related data, because this new feature for policy waiver selection type was delivered in version 189.

Total Legal Violations Waived Per Month

Tracks the number of violations waived each month, categorized by waiver reason. This chart highlights which waiver types are used most frequently over time.

This chart displays the number of violations waived each month, grouped by waiver reason.

Note