AHC Guide.pdf

Guide to the Nexus Vulnerability Scanner

Instantly generate an inventory of your open source and third party
components to determine potential security and license risk.

Gain visibility into the open source components used in an application and discover potential security, licensing, and quality problems. The Nexus Vulnerability Report evaluates your internal and
third party applications for potential vulnerabilities and provides guidance for how to resolve.

• Confidentially and quickly analyze your open source and third party components.

• Create a precise “bill of materials” to identify which open source components are used and
where.

• Discover all component dependencies and known vulnerabilities or license risks.

• Identify known cyber vulnerabilities that may impact software security.

• Discover potential component quality concerns – such as restrictive GPL licenses and age.

• Ideal for Cyber Supply Chain Act initiatives, GDPR, and other regulatory or compliance mandates.

Scope of Analysis

Security Issues

This section identifies the breakdown
of vulnerabilities based on severity
and the threat level it poses to your
application. Severity levels are based
on CVSS ratings.

Policy Alerts

License Analysis

Dependency Depth

This chart shows how deep within
the dependency tree your issues are
located.


Policy Violations

Summary Some components may violate more than one policy. Summary only shows the violation with the highest threat. Use “All” to see every violation associated with each component.
Coordinates This column contains the Maven coordinates for the components found in your evaluation.
Release History Shows where your component (the black bar) falls within the most popular (green bar) and most recent release (blue bar).
Popularity Represents the relative popularity of the component you are using. Larger circles indicate which version of the component is more popular.

Security Issues

Review and investigate any
security vulnerabilities found
in the component in your
application.

Security threat levels shown in
this area do not correspond to
policy, but rather the Common
Vulnerability Scoring System
(CVSS) score.

Component Info

Version Slider
In this Component Detail screen,
compare the security and license
risk of your current component
version to newer versions. Move
the slider to see the newer
component version numbers and
details.

License Analysis

Review and investigate license
information for every component in
your application.

License Threat
Licenses are sorted by threat
level with the riskiest at the top.
Licenses are categorized as
Copyleft (red), Non-standard or Not
Provided (orange), Weak Copyleft
(yellow) and Liberal (blue).

Details

Drill down to see details about
any component license, including
information about declared or
observed licenses, and whether a
newer component version exists.

Scanning
We scan the source
code looking for license
declarations, and determine
if the declared license is
correct or if there is still
hidden risk.


What’s next after your Vulnerability Scan?

Seeing your first Nexus Vulnerability Report can lead to more questions, such as “What can I do
about this?” or “Where do I start?” We’ve helped thousands of organizations answer those questions.

Nexus Firewall: Block undesirable components from entering your software supply chain.

Nexus Repository Manager is an important first step toward improving the overall quality of your
component sourcing, sharing, storage and deployment process. When you augment your repository with Nexus Firewall, you can establish policies to block undesirable binaries from entering the
repository and being released to staging.

Nexus Lifecycle: Automate open source governance across your entire SDLC.

Your free report gives you enough information to start remediation in your application(s) right away,
however the goal is to keep undesirable components out of your software to minimize the impact
of un-planned work on your development teams and ensure your applications are secure.

With Nexus lifecycle, you can define and enforce open source policies at any point in your software development life cycle.

Nexus Auditor: Advanced, continuous monitoring of your production applications.

Nexus Auditor allows you to define policies and evaluate the quality of components used within
production applications. Understand your risk exposure for third party applications or apps no longer being actively developed with customizable dashboards.