Step 7 - Sonatype CLM and Continuous Integration Server Usage (optional)
At the core of open source governance with Sonatype CLM is the concept of enforcement points. An enforcement point represents a stage in the component and development lifecycle, for example, the CI exists in what we refer to as the Build CLM stage.
At each CLM stage, and in conjunction with policy, you have the opportunity to take specific actions. These can range from providing a warning, creating a failure, or sending out email communication. Of course, all of these are based on a component, or components, violating your policies.
This guide will walk you through installation, configuration, and basic usage for the Sonatype CLM for CI enforcement point. It is important to remember that policy is still managed via the Sonatype CLM Server, which is covered in the first six steps.
Note
Sonatype CLM for CI is an optional step to the Nine Steps for Open Source Governance. Depending on your particular purchase, you may not have access to this tool.