Research with Sonatype Guide

Research with Sonatype Guide

Sonatype Guide makes trusted open-source intelligence more discoverable. The Components and Vulnerabilities pages provide an indexed search experience that helps you quickly identify secure, high-quality components using Sonatype’s authoritative data.

From these pages, you can search for components or vulnerabilities and refine results through filters to find the most relevant information for your needs.

Search for Components or CVEs

While there are separate tabs where you can filter through components or vulnerabilities, you can also search between them using either the search that appears on the Home screen or from the main Search for components or CVEs search bar in the top navigation. Enter at least two characters to search for any component or CVE containing those characters.

Components View

The Components section of Guide allows you to filter components by a number of attributes.

Filter by Component Name or Version

To find a component with a specific name or version, begin typing in the Filter components by name or version search box that appears in the main Components window. The search will automatically begin to populate with results that match the characters you enter.

Filter by Ecosystem

To filter by a specific ecosystem (e.g., Maven, npm, Docker, etc.), select the desired ecosystem checkboxes in the Ecosystem section of the left-hand filter navigation. The list of components will show only those components matching the selected ecosystems.

Filter by Severity

Use the Severity filter in the left-hand filter navigation to see only components for which the latest version has vulnerabilities that fall into Critical, High, Medium, or Low severity categories.

These categories are based on CVSS Scoring:

Filter by Category

You can filter components by certain categories (e.g., CLI, data, UI framework, etc.) using the Category section of the left-hand filter navigation. Select the desired category checkboxes to see only those components that fall into these categories.

Filter by License

Use the License filter in the left-hand filter navigation to see components that have a specific license (e.g., Apache-2.0). Select the desired license type to limit your component search results accordingly.

Filter by Trust Score

Developer Trust Score (DTS) is a 0–100 rating that measures the overall quality, security, and compliance of an open-source component. This score provides a clear, developer-friendly indicator of the overall quality, security, and compliance posture of an open-source component version. It combines multiple data signals into a single, balanced score to help developers and AI-assisted tools make confident decisions.

Understanding Developer Trust Score

The DTS is composed of five key factors. Each factor represents a distinct dimension of trust and contributes to the overall 0–100 score.

Each component's score reflects both its own characteristics and the inherited risk from its direct and transitive dependencies, providing a holistic view of the component's trustworthiness.

DTS Score Ranges

Score Range Trust Level Description
90-100 Excellent Highly trusted, well-maintained, secure components suitable for production use
75-89 Good Reliable components with minor concerns; generally safe for most applications
60-74 Fair Components with some issues present; use with caution and monitor regularly
40-59 Poor Components with multiple concerns; avoid or plan remediation
0-39 Critical Components with significant issues; do not use, find alternatives

Filter By Malware

Use the Malware filter to identify components associated with known malware campaigns or containing malicious code. Select the Malware checkbox to limit results to flagged components that should be avoided or removed immediately.

Select

This filter helps you quickly isolate high-risk components or confirm that selected components are free from known malicious activity.

Filter by License Family

Limit your component search results to certain license obligations by using the License Family filter option in the left-hand filter navigation. Select the checkboxes for your desired license obligations to see only components that meet those specifications.

For more information about the different license families, see our license terminology help documentation.

Filter by Publication Window

Use the Published filter to show components based on their release date. Select a time period (Last 7 days, Last 30 days, Last 60 days, Last 90 days, Last 6 months, Last year, Last 2 years or All) to filter results by when components were published.

Vulnerabilities View

The Vulnerabilities section of Guide allows you to filter vulnerabilities by a number of attributes.

Filter by CVE ID or Description

To find a CVE with a specific ID or description, begin typing in the Filter by CVE ID or description search box that appears in the main Vulnerabilities window. The search will automatically begin to populate with results that match the characters you enter.

Filter by Severity

Use the Severity filter in the left-hand filter navigation to see only vulnerabilities that fall into Critical, High, Medium, or Low severity categories.

These categories are based on CVSS scoring:

Filter by CVSS Score Range

You can use the CVSS Score filter in the left-hand filter navigation to define a range of CVSS scores for which you want to see vulnerability search results. Drag the markers on either end of the scale to define the desired range (from 0.0 to 10.0).

Filter by EPSS Score Range

Use the EPSS Score filter in the left-hand filter navigation to define a range of EPSS scores for which you want to see vulnerability search results. Drag the markers on either end of the scale to define the desired range (from 0.00 to 1.0).

Filter by Malware Applicability

Select Yes or No from the Flags Malware drop-down menu in the left-hand filter navigation to limit vulnerability search results to those flagged or not flagged as being malware.

Filter by Exploitation Known (KEV)

Limit your vulnerability search results to those that are known to be being or not being exploited by selecting Yes or No from the Exploitation Known (KEV) drop-down menu in the left-hand filter navigation.

Filter by Publication Window

Filter by Affected Ecosystem

To filter by a specific ecosystem (e.g., Maven, npm, Docker, etc.), select the desired ecosystem checkboxes in the Affected Ecosystem section of the left-hand filter navigation. The list of vulnerabilities will show only those matching the selected ecosystems.

Search results

No results found