Phase 2 - Reviewing and Assessing Risk

Phase 2 - Reviewing and Assessing Risk

The second part of getting started with Sonatype Lifecycle is to onboard your applications and understand your open-source risk. While you assess your open source risk, you should create a process for addressing risk. Many steps in this part will require a joint decision from product development, application security, and your legal teams.

Application Onboarding

There are several strategies for bringing your applications into Lifecycle. Each method for importing an application corresponds with a different part of the Software Development Lifecycle. The two main methods of onboarding applications are through your source control management (SCM) system and integrating an application with your continuous integration system. The ultimate goal should be to integrate with your CI/CD pipeline, as this lets you use Lifecycle's automation features.

Scanning Applications

This step is where you'll finally begin onboarding your applications. Here you'll set up your pilot applications with Lifecycle and define a process for the rest of your organization to follow.

Assessing Component Risk

As you import the rest of your applications you can Identify the most important violations to remediate. Lifecycle aids in this with policy threat levels.