Reference Policy Best Practices

Reference Policy Best Practices

Baseline your applications using the reference policy that comes with Lifecycle

Policy category Details
Security Risk - security policies aligned with the NIST National Vulnerability Database.

- including Sonatype's exclusive identification of release integrity and namespace conflicting components
License Obligations - Sonatype's legal team has reviewed each license for business-critical obligations

- they are organized licenses into threat groups by legal obligations
Architectural Rules - components flagged for cleanup or poor quality

- including Sonatype exclusive hygiene rating
Other - details around component identity or matching

- proprietary or unknown components

Customize policies to match your existing open-source governance practices

Use application categories to create specific policies for a subset of your applications

Turn on enforcement to block security-malicious components at every lifecycle stage

Sign up for Sonatype's policy workshop

Modifying Policies in Production

Importing policies to a production instance is very destructive

Avoid deleting the reference policies

Avoid creating multiple policies for the same risk

Frequent changes to policies will result in noisy violations and poor metrics

Making changes to a policy may reset the waivers associated with the violation