# Research with Sonatype Guide

Sonatype Guide makes trusted open-source intelligence more discoverable. The _Components_ and _Vulnerabilities_ pages provide an indexed search experience that helps you quickly identify secure, high-quality components using Sonatype’s authoritative data.

From these pages, you can search for components or vulnerabilities and refine results through filters to find the most relevant information for your needs.

## Search for Components or CVEs

While there are separate tabs where you can filter through components or vulnerabilities, you can also search between them using either the search that appears on the _Home_ screen or from the main _Search for components or CVEs_ search bar in the top navigation. Enter at least two characters to search for any component or CVE containing those characters.

## Components View

The _Components_ section of Guide allows you to filter components by a number of attributes.

### Filter by Component Name or Version

To find a component with a specific name or version, begin typing in the _Filter components by name or version_ search box that appears in the main _Components_ window. The search will automatically begin to populate with results that match the characters you enter.

### Filter by Ecosystem

To filter by a specific ecosystem (e.g., Maven, npm, Docker, etc.), select the desired ecosystem checkboxes in the _Ecosystem_ section of the left-hand filter navigation. The list of components will show only those components matching the selected ecosystems.

### Filter by Severity

Use the _Severity_ filter in the left-hand filter navigation to see only components for which the latest version has vulnerabilities that fall into _Critical, High, Medium,_ or _Low_ severity categories.

These categories are based on CVSS Scoring:

- **Critical** – CVSS >= 9
- **High** – CVSS >= 7 and < 9
- **Medium** – CVSS >= 4 and < 7
- **Low** – CVSS >=0 and < 4

### Filter by Category

You can filter components by certain categories (e.g., CLI, data, UI framework, etc.) using the _Category_ section of the left-hand filter navigation. Select the desired category checkboxes to see only those components that fall into these categories.

### Filter by License

Use the _License_ filter in the left-hand filter navigation to see components that have a specific license (e.g., Apache-2.0). Select the desired license type to limit your component search results accordingly.

### Filter by Trust Score

Developer Trust Score (DTS) is a 0–100 rating that measures the overall quality, security, and compliance of an open-source component. This score provides a clear, developer-friendly indicator of the overall quality, security, and compliance posture of an open-source component version. It combines multiple data signals into a single, balanced score to help developers and AI-assisted tools make confident decisions.

**Understanding Developer Trust Score**

The DTS is composed of five key factors. Each factor represents a distinct dimension of trust and contributes to the overall 0–100 score.

- **Security:** Measures the version’s exposure to known vulnerabilities. Versions with critical or exploitable vulnerabilities are scored harshly, while versions with no known threats receive the highest scores.
- **License:** Assesses the legal risk and obligations associated with the version’s open source license. This helps teams avoid compliance issues and intellectual property conflicts.
- **Popularity:** Gauges how widely used and trusted a version is within the global developer community by analyzing public download data and real-world usage patterns.
- **Age:** Determines how up-to-date a version is relative to both its own release history and the broader ecosystem. Obsolete or significantly outdated versions receive lower scores.
- **Release Stability**: Evaluates the maturity of a release. Pre-releases (such as alpha or beta versions) and bad releases that were quickly replaced by hotfixes are penalized to discourage adoption of unstable versions.

Each component's score reflects both its own characteristics and the inherited risk from its direct and transitive dependencies, providing a holistic view of the component's trustworthiness.

**DTS Score Ranges**

| Score Range | Trust Level | Description |
| --- | --- | --- |
| 90-100 | Excellent | Highly trusted, well-maintained, secure components suitable for production use |
| 75-89 | Good | Reliable components with minor concerns; generally safe for most applications |
| 60-74 | Fair | Components with some issues present; use with caution and monitor regularly |
| 40-59 | Poor | Components with multiple concerns; avoid or plan remediation |
| 0-39 | Critical | Components with significant issues; do not use, find alternatives |

### Filter By Malware

Use the _Malware_ filter to identify components associated with known malware campaigns or containing malicious code. Select the Malware checkbox to limit results to flagged components that should be avoided or removed immediately.

Select

- **Yes** to display only components that have been flagged for malware and should be avoided or removed immediately.
- **No** to display only components that have not been associated with known malware.

This filter helps you quickly isolate high-risk components or confirm that selected components are free from known malicious activity.

### Filter by License Family

Limit your component search results to certain license obligations by using the _License Family_ filter option in the left-hand filter navigation. Select the checkboxes for your desired license obligations to see only components that meet those specifications.

For more information about the different license families, see our [license terminology help documentation](https://help.sonatype.com/en/license-policy-governance.html#license-terminology "License Terminology").

### Filter by Publication Window

Use the _Published_ filter to show components based on their release date. Select a time period (Last 7 days, Last 30 days, Last 60 days, Last 90 days, Last 6 months, Last year, Last 2 years or All) to filter results by when components were published.

## Vulnerabilities View

The _Vulnerabilities_ section of Guide allows you to filter vulnerabilities by a number of attributes.

### Filter by CVE ID or Description

To find a CVE with a specific ID or description, begin typing in the _Filter by CVE ID or description_ search box that appears in the main _Vulnerabilities_ window. The search will automatically begin to populate with results that match the characters you enter.

### Filter by Severity

Use the _Severity_ filter in the left-hand filter navigation to see only vulnerabilities that fall into _Critical, High, Medium,_ or _Low_ severity categories.

These categories are based on CVSS scoring:

- **Critical** – CVSS >= 9
- **High** – CVSS >= 7 and < 9
- **Medium** – CVSS >= 4 and < 7
- **Low** – CVSS >=0 and < 4

### Filter by CVSS Score Range

You can use the _CVSS Score_ filter in the left-hand filter navigation to define a range of CVSS scores for which you want to see vulnerability search results. Drag the markers on either end of the scale to define the desired range (from 0.0 to 10.0).

### Filter by EPSS Score Range

Use the _EPSS Score_ filter in the left-hand filter navigation to define a range of EPSS scores for which you want to see vulnerability search results. Drag the markers on either end of the scale to define the desired range (from 0.00 to 1.0).

### Filter by Malware Applicability

Select _Yes_ or _No_ from the _Flags Malware_ drop-down menu in the left-hand filter navigation to limit vulnerability search results to those flagged or not flagged as being malware.

### Filter by Exploitation Known (KEV)

Limit your vulnerability search results to those that are known to be being or not being exploited by selecting _Yes_ or _No_ from the _Exploitation Known (KEV)_ drop-down menu in the left-hand filter navigation.

### Filter by Publication Window

### Filter by Affected Ecosystem

To filter by a specific ecosystem (e.g., Maven, npm, Docker, etc.), select the desired ecosystem checkboxes in the _Affected Ecosystem_ section of the left-hand filter navigation. The list of vulnerabilities will show only those matching the selected ecosystems.

## Search results

No results found
