Documentation Nexus IQ Server 1.19

Our documentation site has moved. For the most current version, please see http://help.sonatype.com

Sonatype CLM 1.9

The 1.9 release of Sonatype CLM introduces a wide range of expanded functionality that encourages improved categorization of your applications, as well as a number of new features aimed at helping you fine-tune your policies.

The features and improvements for this release affect the following CLM components:

  • Sonatype CLM Server
  • Sonatype CLM Stand-alone Scanner
[Note]

Depending on what components your company has purchased and/or uses, you will want to make sure you update your entire Sonatype CLM Suite.

What’s New in Sonatype CLM 1.9

At the core of this release is the introduction of Tags. Tags provide a way to identify specific characteristics that applications share, and direct policies to be matched to applications with those tags.

We’ll discuss tags in more detail in the next section. However, in addition to tags, this release also includes improvements to:

  • Waivers - entire policies can now be waived. This can range from waiving a single component, to waiving all components for all applications.
  • Reporting Area - the Reporting Area dashboard now includes the organization, allowing you to search for, and sort by, organizations.
  • Various UI Improvements - among a number of small tweaks and improvements, you can now identify your specific version of Sonatype CLM.
  • Stand-alone Scanner - users can now specify a location for a JSON file, which includes information about the completed scan, and a URL to the Application Composition report.
  • Application Composition Report - The report has been updated to provide a number of new views on the policy tab, including specific icons and views for identifying components that have been waived.
  • Security vulnerability identified and fixed.
  • Various small bug fixes.
  • All documentation has been updated to reflect all new features. Documentation can be accessed via the help area in Sonatype CLM, or in our Sonatype CLM Documentation area on our website.

More About Tags

As we mentioned, tags provide a way to identify common characteristics (e.g. distributed) for applications in your organizations. Tags are created at the organization level, and then be applied to individual applications. Not all applications will (or should) have the same tags, which is where the next element of tags, gives you even more flexibility in fine-tuning your policies and policy management processes.

Policies now have an additional option which allows you to select certain applications based on their tags. If an application has applied this tag, it will be evaluated against that policy. Now, you have an easy way to establish both more relaxed, as well as more stringent policies, depending on the risk or level of quality associated with the application.

There’s even more to tags than policies and applications though, this latest feature also includes:

  • Tag Colors - In addition to custom tag names and descriptions, the color of each tag can also be selected.
  • Tag Import - When importing sample policies, tags will also be included.