Video: Software Composition Analysis Office Hours: Code Insight 2026 R3 Release Overview | Duration: 1564s | Summary: Software Composition Analysis Office Hours: Code Insight 2026 R3 Release Overview | Chapters: Session Welcome & Agenda (5.9199999999999875s), Welcome and Introduction (5.92s), 2026 R3 Release (70.68499999999997s), Infrastructure Enhancements (166.58999999999995s), License Expression Support (283.56999999999994s), Policy Rules Q&A (638.395s), Custom License Snippets (672.905s), Archive Project Feature (757.305s), Bulk Import Licenses (863.865s), Miscellaneous Updates (993.9649999999999s), Q&A Session (1162.635s), Stability and Roadmap (1206.81s), Q&A and Closing (1432.47s)
Transcript for "Software Composition Analysis Office Hours: Code Insight 2026 R3 Release Overview":
Alright. Hello, everyone. Thanks for joining, yet another session of our, SCA office hours. Firstly, you know, I'd, like to thank a moment for all our, users who have been consistently joining our, quarterly officers. Thanks a lot. Thanks a lot for your time and, just trying on trying to understand what we are doing on our SEO solution. So with that said, let's quickly talk about the agenda. Probably, today's is going to be a shorter one, but let's take a quick look at, you know, what we are up to. So today, we're going to take a quick look at, what we have in our twenty twenty six r three release. So we have the release coming out today. You should be able to see down see the release in your PLC, coming in later today, or maybe it's already there. And then we'll also talk about what we are planning to do for twenty twenty six r four. And let's, with that, let's start with, what Christine has said. So I for the sake of repetition, we have yet another user group coming up in this year. We don't want to, miss the tradition. So we've been doing user groups for a really long time now. And, after our, COVID, we have switched completely to virtual. And, this time also, it's going to be a virtual, and I will be a small, shorter session this time, so it should be around ninety minutes. I have a lot of, topics and interesting topics for you to, you know, discuss and, you know, talk to your fellow users at SCA. So it'd be a great interaction for those who have been using SCA for a long time. So the event as such is on September 23. So please, click on the link in the chat, and, we request everybody who has joined us to register for it, you know, block your calendars. I guarantee you that ninety minutes will be well. No time well spent. K. With that said, let's quickly start, what we have in store for 2026 r '3. So it's going to go it's going to release today, 2026 r three. So we have done the first item we have as one on the as one management team, we have the first item as the support for and our licensing model. I'm gonna talk about that in the subsequent slides. We also have the ability to add custom license evidences, and, we have refreshed our Rust package collector. We noticed that the excuse me. Excuse me. We noticed that the collector was not running up to date and that it had a lot of stale packages when we had to go and correct it. So now the Rust packages are now up to date. On the infrastructure side, we have a couple of enhancements here. First thing is, a lot of noise getting created with vulnerability alerts of those projects which you are no longer interested. So we have introduced a new setting in the project summary page, which helps users to deliberately subscribe for alerts or unsubscribe for alerts if they do not wish to be alerted. So it just not it not just adds, functionality to, expand the vulnerability alerts to beyond project owners or project contacts, so anybody in the project or anybody in the system can actually subscribe to the vulnerability alerts on any project. And the next one, which includes a full parity of agents with scanners. So, this is one more thing we have been working on for a while now. So one of the things that we keep hearing is that the scanner is, too heavy, and sometimes we'd want to have all the features available in the scanner on the agents as well so that we can continuously run them in our pipelines. So with this release, we'll have that as well. So another infrastructure item is the SIEM support for Azure. So this is a an advanced LDAP integration that has been requested by some of our users, so we now have the support for it. We're gonna talk about the ability to archive projects. And on the miscellaneous side, we have, bulk import policy upload using where the UI and the API. And, we have full support for CVSS v four in Core Insight now. We are beginning to see increased vulnerabilities on NVIDIA and other portals with, CVSS v four scoring. So we now have the support in Core Insight. And, some old scan profiles, now we we'd not have the ability to delete them, so we have included, that support as well. And on the data side, we have vulnerability fixes on the Maven Collector. They're coming in. There's a start to it. The work is underway and it work is really progressing well. And we hope to release this update as a part of our August update. So what's the first one? The first one is, support for license expressions. So up until now, what we had in code insight is, only the support for a single license selection. So in many cases, what you would have noticed is inventory name which says, foobar a or b license. In reality, the license selected license was always minus one or just say I don't know. What we now have done is that it is a continuous exercise from our data collection and also supporting the product. What we've done really is that we have collected the license expressions as is from sources. What I mean by this is, like, for example, if you take NPM or Alpine, in these two forties or in these two collections, what we actually get as the license expressed is a true license expression. You know, either it is a single license as MIT or, you know, sometimes in case of a a complicated company, it could actually be MIT or ISC license. We used to collect those, but, you know, we should discard the expression. So what we're now doing is we're actually collecting the expression as is and presenting it to code inside. The way you could actually leverage that is the scan would create a license expression. And the scan runs into a component that is available from the source as a license expression with an ARB license or an ANDB license. It would create a license with a license expression. In this case, the selected license will not just be a single license, but the selected license will be a selected license expression. So the resulting inventory will be a something like foobar a and b license. So this would accurately help, express your open source components in the SBOM so that you can declare the licenses accordingly. And, a small word that is pending out here today, but we hope to be closing by end of next week is, the reports that are available in our public GitHub also will be updated to leverage this license expression attribute. And, the existing report of project report will all has already been updated in the product, but every other report that is outside of the product, which is in our GitHub repository, will be updated to leverage this functionality as well. So all the attributes of an s p d x license or a cyclone d x license will now be updated to the license expression. Now it also comes with a little bit of a, recall, a, you know, limitation, coming in from the sources. So some of the sources actually give us the true license expression if you think about 10 PM and Alpine as I said. So they are able to provide us what is the original license expression that the user has, chosen or the original open source author has chosen. But some of the licenses at source are nondescriptive. You know, they're not, they don't come with any expression. So examples are, that I can think of are Python, PyPy, and, we also have package.go.dev, the go packages. So both of them not really have a true way of expressing the license, except that, you know, they give us an, you know, a collection of licenses for a given version. So in those cases, what we do in the product would be that we will be able to apply a given license, apply a given, you know, and or or apply a given, license expression in an R format, allowing the users to pick and choose which license they would want to do. Like for instance, there is a PyPy component which says, I am licensed under MIT, comma ISC because the source doesn't actually apply that. In those cases, what we do is we default it to an R expression by default, and, you would be able to understand that it is an R expression by default. And there's also a advanced search filter that will help you understand where further review of the license is required versus where it is not. So this would help us, help you, essentially, in understanding whether the license is expressed as is from the source or we have defaulted it to an r expression. In both the cases, you would have the option to go ahead and select a single license. Now combining this with our, earlier release feature, which is a license ranking feature, so this gives us a good opportunity for you to leverage the license ranking feature for all the safe licenses. Let's say, for example, there are a ton of or a gazillion of, p three licenses or, you know, chip or missing licenses, And then you would you're wrap your, largely okay with, you know, selecting MIT or something else or Apache two point o or something else. So you can now define your license ranking order available in the settings page. And, if the license ranking order setting is enabled and we, deduct a license as an r license, in both the cases of whether the expression is available at a source or the expression is not available at a source, we will honor the license ranking and automatically update the inventory item with a single selected license of an odd license of the selected license. And, the same attribute will be, available everywhere, the same. So inventory data model has been updated across the board, and, the license expression should be carried forward when you do a project copy, when you do a, project export import. All of the inventory attributes will be carried forward along with the new new new attribute called the license expression. So there's a good question from Christine. How does the policy rules and usage guidelines apply when using and or or license selection? So at this point of time, thanks a lot, Laurie. So we have it in our roadmap to add, the license expressions also as a part of, policy. Do not have it yet. Concurrently, the license the policy fires only on a single license selection. The policy does not fire on a, a multiple license expression. Alright. This is one more feature that, has been requested by a few of our customers, you know, more than a couple, where there is a proprietary license that, you know, users are using, and we would want the proprietary license to be identified as a license evidence and then be presented to the user along with the highlighting. So there is no UI feature to add a custom snippet, but what we have done is there is a REST API available. It's pretty robust. So what you can do is you can go ahead and add a custom license snippet in there, which and, invoke the API. And the new custom license to get along with your license will actually be created as a license evidence mapping. And you scan a project and there is a, particular license that particular snippet available in the project that has been identified. So we'll be able to mark that as an evidence. This will be particularly useful in the detection of proprietary licenses, or in some cases, we'd want to do an s p d x ref. So in both the cases, we'd be able to ensure that the SPDX ref and, any kind of long license text coming in from your property licenses would actually be identified as license evidence, and you'd be able to filter them as any other evidence available in the analysis workbench. I apologize for the garbled image here. So please ignore the overlay, image. So this feature is the archive project feature. So we have we now have a new functionality in at a project level called archive projects. So this is our solution for, a an archival mechanism for projects. So one of the requisite we keep getting is that we have, you know, a code inside system is getting huge and there's so many projects in the system and the disk space is really a problem, but we'd not really want to lose the record of all the existing projects. We'd want to keep all the projects, but just the project data, but, not the actual files in there. So what we're gonna do for this particular thing is that we're gonna we created a new project new option called, archive project. What archive project essentially does is it will help you keep the project reports and the project data, the export, project exported data, and all the product inventory view, the in fact, even the analysis workbench details, the evidences, all of that, but it will essentially delete the underlying code based files. So this is as good as, you know, one of our customer uses word in a locked project. So this is essentially as similar to, you know, locking down a project, you know, which, you know, nobody wants to touch it. But, you know, everything in the, everything in the project will be in a read only view. There is nothing to actually act upon it, and this is an irreversible action. We would like wise users to use it with caution. This is not, archive and unarchive. There is no such thing as, reversing an archive project. So the project will continue to be available in the system, but the data underlying data is lost. The moment you do an archive project, the entire project becomes lead only. There's no user action that can be performed. The next one is, bulk import licenses. Again, one of the most, requested feature in the recent past is the ability to bulk import licenses into a policy. And, every time, there is a new addition or a bunch of additions into a license license policy, it is a painful process to upload or update or add the policies and, and to understand first whether the policy is available in the screen or not. I will the licenses available are already added to the policy or not. So this particular bulk import would actually, this bulk import would actually go ahead and add a bunch of licenses into the license into the license into the into the licenses section of the policy. So the schema would be available as to how you'd want to define the CSV if you do an export. You can also export the entire thing by into a small CSV file. And all you need to do is update your CSV file and also takes into account the usage criteria. So you don't have to redo a lot of that in the UI. You can just update the CSV and upload it. This functionality is available both in The US side, and there's also a REST API for it. There's a question from Laurie. Who has permission to acquire a project since it's not reversible, like, openly system admin and not project admin? It is available to project admin, Laurie, because a project administrator has the right to take action on it. And I will work with you to see if this doesn't work and probably see how we can mitigate any any that's a good one. So prior to administrator often does things, you know, they shouldn't. Yeah. I I I get it. I understand. But then, you know, prior to calling in a system admin to archive projects might be a little bit of an overhead. The system admin is supposed to be doing only system level setting changes, but then the project admin, would have naturally the permissions to take a call on the project. We can work with you and figure out, you know, if there is an alternative to it. Right? Thanks for the feedback. Alright. A few miscellaneous items before we move on is, the first one is full agent parity, with scanners, and scan agents will now have full scan parity with the scanners. So but up until now, the agents could only collect license evidences, but starting, twenty twenty six r three, the agents have full capability to scan as good as the scanners and also report back, any evidences. It could be licenses. It could be copyrights. It could be email alerts. Any of those evidences back to the core server and so that analysis or, analyst can go ahead and look at what evidences are being collected. And there's no difference between how the scanners do it or the agents do it. It's all the same logic behind the scenes. But what this enables is, for those automated projects where you would want to go ahead and run them in multiple agent machines, there, we do not have an impairment that the the scans are getting backed up because of the queue. So the scanners the agents would take care of the heavy lifting on distributed machines, and the scanners would actually be free for those machines for those projects where you want to do a deep dive analysis and want access to all the all the files on the project. And without the word, the vulnerability subscription at the project level, so users can choose subscribe or unsubscribe to alerts. Again, so so far, the vulnerability alerts were only limited to, the the project contact or the project, owner. You know, back in the day, we used to call them owner. So it was available only to the project contact. So what this now allows is, if I'm a project contact, I'll be able to subscribe or unsubscribe to any vulnerability alerts. Or if I'm not a project contact and I'd want to just watch this project for vulnerabilities, I can do that as well. So the option is available for any user in the system. Anybody can get alerted on any any project. At the same time, if, every old project a two year old project, I don't want to receive vulnerable emails, I'll just go ahead and uncheck all of them. One thing that's not written here is also the vulnerability email will also have an unsubscribe, link in there. So we'll be able to go ahead and click on that, and they'll no longer be able to subscribe to the long no longer be able to receive the alerts on the vulnerability, emails. The last one here is deleting the scan profiles. It's more of a cleanup activity. We now have the ability to delete scan profiles, and, it's a small, you know, nifty improvement we've done here, which is, if the scan profile is in use in any projects, we offer an option to choose a replacement scan profile before deleting it. And if the scan profile is not used in any projects, we just go ahead and delete them. Here's a question from Laurie. Project contact can opt out of alerts. Yes. So any user on the system, you know, can go ahead and opt themselves out of the alerts. And there's one more question. ADO agent would be the same type of scan as a server based scan. ADO agent, the agent is, ADO agent typically is based off of an agent. So it would be similar to the agent itself. And now with this release, it would have full parity with the scanner scan. Alrighty. Thank you. He's happy. Alright. We have so there's not a lot to talk about 2026 r four, and I'll explain why. And, you know, we are the last release of the year, and, we are being quite deliberate about this. So we want to ensure that, some of the stability issues on the system are taken care of. So I'm not claiming any, road map features at this point of time for twenty twenty six r four. Having said that, there will be a, you know, feature here and there. There will be a toggle here and there. There will be an advance that's here and there. But then at this point of time, the focus of q four of this year is, ensuring that the system is more stable than ever, ensuring that, you know, the any detection issues that we have been finding, that have been backed up because of the new feature development, All of those issues are prioritized in full release rather than just, you know, cherry picking them in each release. Having said that, I will also maintain that now there will be, teeny tiny features or tiny improvements here and there. But the focus of the entire q four release will be to improve performance of not just the, you know, scan process, the overall system as a whole, and also trace, you know, code inside. So, you know, these code inside because of its detection capabilities. And sometimes we see a false positive. Sometimes we use we, do not associate a file properly. Sometimes we do not identify an inventory item. So r four release is going to be primarily be around the performance and detection issue fixes. And, you know, there are a few features we want to talk about, not claiming victory yet, but I think we're making decent progress on, in AI model as an inventory item. So I I did not want to talk a lot about it, but we are exploring, AI model as an inventory item where you would have the, inventory item today can create a type component, license only, or a work in progress. So what we're hoping to do is also in our four, we will also have, a type is equal to an AI model because we see that, models are largely there is a lot of usage of AI models in source code, and we, we intend to have, like, a model card in coding site, which will show and express the AI models. It's a question again from Lavi. Dynamics cancel or our load balancing in the past, it was noted that, you know, we could create a case to get on beta testing with this. We haven't because of other issues. Is that going to be a standard encoder still in real? It continues to be in a closed loop. We're working with a few customers, Laurie, and thanks a lot for, you know, coming on board with this. You know, feel free to reach out to us, and, we'll help you how to, you know, set up the dynamic scanner and, and we'll see how it actually fares compared to in the previous one. Because the scan the dynamic scanning is very, very, environment dependent, and we'd want to take it a little slow. And, we're happy to, you know, work with you on your staging environment and see, you know, how it fits very closely and know before we, promote it to a, production environment. But, yes, in our test, it has been stable. And, while the r three slide doesn't talk about it, we have added a significant performance improvements to the dynamic scanning as well. The upload was a pain point, and we have gotten the upload code base to a the a very similar parity on, the non dynamic scanning approach. Alright. That's all I had, for today. Any questions? Anybody wants to come off mute and, you know, ask something or you won't have a question and you'd want to, drop it in the chat? That's, I'll go ahead and give folks I don't see anything currently in the in the chat, Venkat. I did, while we're waiting for folks, if you guys are still digesting or or preparing your questions for Venkat, quick plug for, event survey. Go ahead and click that give feedback button. If there's any any anything you'd like to give us in terms of, like, feedback on the format, the content, the product, that type of thing, please, you know, just shoot us a message using the give, feedback button there. And, again, for those, if you did join, you know, a little late, the under the docs tab is the a copy of the presentation that Venkat just went over as well as the link to our user group. No questions yet? Cool. Alright. And then as I said, feel free to you know, if you come up with questions after the fact, please do just send them over to, to us and, you know, we'll get back to you guys as soon as we can. Anything else, you'd like to to say, Venkat? No. Thanks a lot. Thanks a lot for joining us today, and, we really, request everybody who has joined to join our user group. Yeah. Thank you. That'd be good times. Alright. And thanks again, Venkat, for for covering the the latest release, which is available today, guys, so you guys can download it. Alright. Have a good one. Take care, everyone. Thanks again for your time. Bye bye.