Repository Health Check

Repository Health Check

Repository Health Check (RHC) allows Nexus Repository users to identify risks using open-source components currently found in their proxy repositories. Limiting the impact of open-source risk at the earliest stages is key to reducing rework and protecting your DevOps pipeline from bad actors.

  1. Open-source components with security vulnerabilities ranked by severity.
  2. License warnings per component are categorized by their obligations to the organization.
  3. A detailed report that identifies specific artifacts and threats and when they are being downloaded.
  4. RHC may analyze components in the following formats:
Maven, npm, NuGet, PyPi, RubyGems, Yum

Configuring Repository Health Check

To use Repository Health Check, sign in as an administrator to the Nexus Repository instance.

  1. Navigate to the Repositories view under the Settings menu
  2. Observe the column labeled Health Check

The Analyze button displays when RHC is not enabled.

Two icons with numbers are displayed when RHC is configured:

  1. Select the Analyze button to enable RHC on a repository
  2. A dialogue box will appear and offer you the option to enable RHC on all supported repositories or just the one you've selected. Select either Yes, all repositories, or Yes, only this repository to enable RHC for the selected or all repositories. Select No if you wish to cancel.
  3. An analyzing status appears as the scan begins. The initial scan will take some time with the resulting report will initially appear blank.

Enabling RHC creates and schedules the below task for each repository with RHC enabled. While the task is set to run once an hour, it only generates a new report once every 24 hours. Running the task again does not update the report.

System - Repository Health Check
  1. Hovering over the Health Check column entry will show the summary report once the scan completes. New repositories without proxied components will show a blank table. The data gradually fills out the summary as users download components.

Repository Health Check Summary Report

Nexus Repository Community users will see the following summary report after the analysis of the repository is complete.

This summary report displays the following information:

The following is in the Issue Summary section:

The scoring is standardized on a 1-10 scale based on the Common Vulnerability Scoring System (CVSS); Only the highest risk on the component is included in this count. Displays a count of the components with Critical (7-10), Severe (4-6), and Moderate (1-3) vulnerabilities.

Displays a count of the components with the following license warnings:

Detailed Repository Health Check Report

Nexus Repository Pro users may select the View Detailed Report button to access a detailed report.

The detailed report shows the summary along with a table of component issues:

From the View By drop-down menu, you can also select the Vulnerabilities option.

From this view, the detailed report shows the following information:

Resolving Certificate Errors and the Health Check: Configuration Capability

The RHC service works by performing calls to the following Sonatype data services depending on the Nexus Repository license agreement in use. Network administrators need to allow these URLs through their network firewall to receive updates.

https://rhc-pro.sonatype.com
https://rhc.sonatype.com

Administrators run into certificate errors because they are using a firewall proxy server that rewrites the certificate, making it appear untrusted. Resolve the issue by configuring outbound SSL, adding the necessary certificates to the Nexus Repository trust store, and using the Nexus truststore option when configuring the capability.

Modify the Repository Health Check Capability

To manage the existing capability, complete the following steps:

  1. Navigate to Settings → System → Capabilities
  2. Select the Health Check: Configuration type from the Capabilities table
  3. Select Settings
  4. Select Use the Nexus truststore checkbox to allow Nexus Repository to manage the SSL certificate of the remote repository
  5. Select Save

Disabling Repository Health Check

Disable RHC through the API. To learn more, see our API documentation, which you can access via the Nexus Repository user interface under Settings → System → API. Look for the following endpoint in the Repository Management section.

DELETE /v1/repositories/{repositoryName}/health-check