Research with Sonatype Guide
Research with Sonatype Guide
Sonatype Guide makes trusted open-source intelligence more discoverable. The Components and Vulnerabilities pages provide an indexed search experience that helps you quickly identify secure, high-quality components using Sonatype’s authoritative data.
From these pages, you can search for components or vulnerabilities and refine results through filters to find the most relevant information for your needs.
Search for Components or CVEs
While there are separate tabs where you can filter through components or vulnerabilities, you can also search between them using either the search that appears on the Home screen or from the main Search for components or CVEs search bar in the top navigation. Enter at least two characters to search for any component or CVE containing those characters.
Components View
The Components section of Guide allows you to filter components by a number of attributes.
Filter by Component Name or Version
To find a component with a specific name or version, begin typing in the Filter components by name or version search box that appears in the main Components window. The search will automatically begin to populate with results that match the characters you enter.
Filter by Ecosystem
To filter by a specific ecosystem (e.g., Maven, npm, Docker, etc.), select the desired ecosystem checkboxes in the Ecosystem section of the left-hand filter navigation. The list of components will show only those components matching the selected ecosystems.
Filter by Severity
Use the Severity filter in the left-hand filter navigation to see only components for which the latest version has vulnerabilities that fall into Critical, High, Medium, or Low severity categories.
These categories are based on CVSS Scoring:
- Critical – CVSS >= 9
- High – CVSS >= 7 and < 9
- Medium – CVSS >= 4 and < 7
- Low – CVSS >=0 and < 4
Filter by Category
You can filter components by certain categories (e.g., CLI, data, UI framework, etc.) using the Category section of the left-hand filter navigation. Select the desired category checkboxes to see only those components that fall into these categories.
Filter by License
Use the License filter in the left-hand filter navigation to see components that have a specific license (e.g., Apache-2.0). Select the desired license type to limit your component search results accordingly.
Filter by Trust Score
Developer Trust Score (DTS) is a 0–100 rating that measures the overall quality, security, and compliance of an open-source component. This score provides a clear, developer-friendly indicator of the overall quality, security, and compliance posture of an open-source component version. It combines multiple data signals into a single, balanced score to help developers and AI-assisted tools make confident decisions.
Understanding Developer Trust Score
The DTS is composed of five key factors. Each factor represents a distinct dimension of trust and contributes to the overall 0–100 score.
- Security: Measures the version’s exposure to known vulnerabilities. Versions with critical or exploitable vulnerabilities are scored harshly, while versions with no known threats receive the highest scores.
- License: Assesses the legal risk and obligations associated with the version’s open source license. This helps teams avoid compliance issues and intellectual property conflicts.
- Popularity: Gauges how widely used and trusted a version is within the global developer community by analyzing public download data and real-world usage patterns.
- Age: Determines how up-to-date a version is relative to both its own release history and the broader ecosystem. Obsolete or significantly outdated versions receive lower scores.
- Release Stability: Evaluates the maturity of a release. Pre-releases (such as alpha or beta versions) and bad releases that were quickly replaced by hotfixes are penalized to discourage adoption of unstable versions.
Each component's score reflects both its own characteristics and the inherited risk from its direct and transitive dependencies, providing a holistic view of the component's trustworthiness.
DTS Score Ranges
| Score Range | Trust Level | Description |
|---|---|---|
| 90-100 | Excellent | Highly trusted, well-maintained, secure components suitable for production use |
| 75-89 | Good | Reliable components with minor concerns; generally safe for most applications |
| 60-74 | Fair | Components with some issues present; use with caution and monitor regularly |
| 40-59 | Poor | Components with multiple concerns; avoid or plan remediation |
| 0-39 | Critical | Components with significant issues; do not use, find alternatives |
Filter By Malware
Use the Malware filter to identify components associated with known malware campaigns or containing malicious code. Select the Malware checkbox to limit results to flagged components that should be avoided or removed immediately.
Select
- Yes to display only components that have been flagged for malware and should be avoided or removed immediately.
- No to display only components that have not been associated with known malware.
This filter helps you quickly isolate high-risk components or confirm that selected components are free from known malicious activity.
Filter by License Family
Limit your component search results to certain license obligations by using the License Family filter option in the left-hand filter navigation. Select the checkboxes for your desired license obligations to see only components that meet those specifications.
For more information about the different license families, see our license terminology help documentation.
Filter by Publication Window
Use the Published filter to show components based on their release date. Select a time period (Last 7 days, Last 30 days, Last 60 days, Last 90 days, Last 6 months, Last year, Last 2 years or All) to filter results by when components were published.
Vulnerabilities View
The Vulnerabilities section of Guide allows you to filter vulnerabilities by a number of attributes.
Filter by CVE ID or Description
To find a CVE with a specific ID or description, begin typing in the Filter by CVE ID or description search box that appears in the main Vulnerabilities window. The search will automatically begin to populate with results that match the characters you enter.
Filter by Severity
Use the Severity filter in the left-hand filter navigation to see only vulnerabilities that fall into Critical, High, Medium, or Low severity categories.
These categories are based on CVSS scoring:
- Critical – CVSS >= 9
- High – CVSS >= 7 and < 9
- Medium – CVSS >= 4 and < 7
- Low – CVSS >=0 and < 4
Filter by CVSS Score Range
You can use the CVSS Score filter in the left-hand filter navigation to define a range of CVSS scores for which you want to see vulnerability search results. Drag the markers on either end of the scale to define the desired range (from 0.0 to 10.0).
Filter by EPSS Score Range
Use the EPSS Score filter in the left-hand filter navigation to define a range of EPSS scores for which you want to see vulnerability search results. Drag the markers on either end of the scale to define the desired range (from 0.00 to 1.0).
Filter by Malware Applicability
Select Yes or No from the Flags Malware drop-down menu in the left-hand filter navigation to limit vulnerability search results to those flagged or not flagged as being malware.
Filter by Exploitation Known (KEV)
Limit your vulnerability search results to those that are known to be being or not being exploited by selecting Yes or No from the Exploitation Known (KEV) drop-down menu in the left-hand filter navigation.
Filter by Publication Window
Filter by Affected Ecosystem
To filter by a specific ecosystem (e.g., Maven, npm, Docker, etc.), select the desired ecosystem checkboxes in the Affected Ecosystem section of the left-hand filter navigation. The list of vulnerabilities will show only those matching the selected ecosystems.
Search results
No results found