Documentation Nexus IQ Server 1.19

Our documentation site has moved. For the most current version, please see http://help.sonatype.com

Sonatype CLM 1.11 (Currently 1.11.2)

The most significant improvement in the Sonatype CLM 1.11 release focuses on the development of the new CLM Dashboard. With this, the Dashboard becomes a critical part of your Sonatype CLM Server experience. We’ll talk more about that in just a moment, as well as these additional features, all part of the latest Sonatype CLM update.

  • Application APIs
  • Global Creation
  • Component Identification Improvements
  • LDAP Performance Improvement
  • Various Other Enhancements and Bug Fixes

Affected CLM Tools

The majority of features in this update focus on the Sonatype CLM Server, and will require an upgrade. If you are using any of the following components, you should be sure to upgrade them as well.

  • Sonatype CLM CI Plugin
  • Sonatype CLM IDE Plugin (Eclipse)
  • Sonatype Stand-alone (Command Line) CLM Scanner
  • Sonatype CLM Maven Plugin

Update - Sonatype CLM 1.11.2

This minor update provides a fix for a related security vulnerability, which was identified and fixed.

Update - Sonatype CLM 1.11.1

This minor update includes enhancements for:

  • Sonatype CLM Server updated with new functionality for wildcard usage when searching for users (LDAP or the internal CLM realm). View Documentation
  • Sonatype CLM for IDE (Eclipse) added compatibility for m2e 1.5.

What’s New in Sonatype CLM 1.11

Dashboard

After upgrading to Sonatype CLM 1.11, when logging into the Sonatype CLM Server, you will now be taken to the new Sonatype CLM Dashboard (previously the Reports Area was loaded).

[Note]

Users of Sonatype CLM - Nexus Edition will not have access to the new dashboard.

Based on your permissions (assigned roles), you will see aggregated results corresponding to the applications you have evaluated. In addition to a variety of visual information that includes a View Summary and a Violation Summary, you will also find details related to the newest and highest risk violations a component and an application have incurred.

This data is spread across three main views:

  • Newest
  • By Component
  • By Application

Each of these views can be filtered and sorted as you desire. This lets you dive even deeper into the data with new features like the Component Detail Page which provides up-to-the-moment analysis of your component risk. To learn more about the Dashboard, check out our latest documentation for this area.

figs/web/clm-server-dashboard-default-display.png

Figure 2. Sonatype CLM Dashboard


[Tip]

The dashboard introduces a new concept, called risk, which involves a calculation of threat levels for unique policy violations. Be sure to review the guide for a more thorough explanation.

Application REST APIs

A long awaited feature that has been requested many times, is the ability to create and edit application information via API calls. The latest release of Sonatype CLM now supports this ability.

Among the various features of this new public REST API, the most notable are:

  • Creating and editing an application
  • Setting tags
  • Mapping user roles

For detailed instruction on the use of this feature, check out another of our new guides, The API User Guide.

Global Create

One of the most common actions in Sonatype CLM is the creation of new items. This could be applications or organizations, as well as policies, labels, tags, and license threat groups.

No matter the need, the new Global Create functionality allows you to perform these actions from nearly anywhere in Sonatype CLM. Better yet, if you are already in a particular location, the Global Create button will take this into consideration.

For example, if you were looking to create a new application, and were trying to do so from the organization you wish to use, Sonatype CLM will automatically pre-populate this for you.

figs/web/sonatype-clm-server-global-create.png

Figure 3. Global Create


Component Identification

Two enhancements to component identification have been made:

Claiming Unknown Components
Users have enjoyed the ability to claim components for some time. However, this was previously limited to only those components identified as unknown. Now, users can also claim any component identified as similar, and in these cases, the CIP will remain intact as well. Meaning, you’ll see component data that was matched during the evaluation.
Using Regular Expressions in Proprietary Component Configuration
Sonatype CLM will generally treat internally developed components as proprietary. Configuring CLM to identify the proprietary components is an important part of ensuring evaluation results are as accurate as possible. While proprietary component configuration has always been a feature, users can now use regular expressions when specifying them. For more information on this change please review the proprietary components section of the Application Composition Report Guide.
LDAP Performance
In some cases, especially large implementations, using dynamic groups can produce slow LDAP searches within Sonatype CLM. To address this, group searching can now be turned off or on. Making this change will effect how groups can be mapped to roles in Sonatype CLM. For more information, check out our updated LDAP Dynamic Groups and Security Administration documentation.
Additional Improvements

Various updates to maintain consistency in the UI, as well as modification to address any reported bug have been added to this release. In addition two these general updates, two other features have been removed.

  • Removed procurement stage option.
  • Removed transparent tag color option.
[Note]

Existing clear tags will be changed to white.