Video: Software Composition Analysis Office Hours: Code Insight 2025 R4 Release Overview | Duration: 2184s | Summary: Software Composition Analysis Office Hours: Code Insight 2025 R4 Release Overview | Chapters: Technical Issues Introduction (0s), Release Overview Discussion (15.004999999999995s), SBOM Import Capabilities (1415.97s), Curation Validation Persistence (1504.94s), AI License Application (1699.2849999999999s), SBOM Scanning Updates (1930.285s), Closing Remarks and Farewell (2106.46s)
Transcript for "Software Composition Analysis Office Hours: Code Insight 2025 R4 Release Overview": Hello. Hello. Welcome to yet another session of, the CEO officers. So this will be the November edition and, do the last one for the year. And we're gonna wrap up this year with, an overview of, you know, what we've been working on for the last quarter and, where our key focus ideas are for the next quarter as well. So let me go to the slide. So, yeah, very quickly give an update on our releases, you know, what we're going what we've been working on in our view, our our four, our 2025 r four release, and then what we're gonna work on in, 2026 r one release, and then we'll open it up for q and a. I have a surprise topic, so, you know, hopefully, we'll be able to cover that as well. And, CodeInsight 2025 r four is releasing today. Should probably be available in the product and licensing center already, and we apologize for a week delay, you know, per the plan. So we originally intended to release last week, and we had to, you know, close out on a few issues before releasing. And, we took some additional time to ensure that there are no other issues, and we hardened some more tests, and then we are releasing today. And then we as usual, we will continue with our quarterly cadence, and code insight twenty twenty six hour one will be planned for February, you know, 2026. And as usual, we have the chat open, and then if there are any questions, you know, feel free to drop in them. And if there's contextual, then I'll probably, you know, pause and then noting the questions right away. So let's start with the overview of 2025 r four. And, you know, some of these items, we will not probably go in deep. So we're gonna talk about the SPA management items in deep and, you know, the automated discovery go bind is scanning for dependencies. So this is an item that we have picked up midway during the release, and we got some feedback from, you know, Ria, I think, you know, and then we, you know, went ahead and looked at, you know, how easy your difficulties, and we figured that we can actually detect, you know, dependencies from go binary, okay, in a very accurate fashion. And then we ensured that we, we added it to the release and complete in time. And, we'll talk about reports in a bit and some miscellaneous items in there, which are, in the, you know, miscellaneous items, which is additional attributes for the hosted usage. So we added, you know, some more attributes, for the usage guidance, you know, usage attributes, in the inventory, especially for the hosted, you know, parameter. And, some nifty improvements in the suppressed vulnerabilities, you know, page where, you know, we had some filters in the global, vulnerability suppression page, but we did not have any filters in our project vulnerability suppression page. So we added additional filters for, ease of access to understand which vulnerabilities are suppressed in the, project vulnerability suppression page. You could filter by vulnerabilities. You would filter by component. You would filter by a project. And, a couple of other, handy items, which are the ability to delete custom components, you know, custom licenses and custom versions. So all of them are now available, you know, for deletion as well. We have we had a rest API for deleting custom licenses, and we extended that support for, you know, deleting custom components and custom versions as well, k, from the UI and, deleting licenses from the UI as well. And what would happen is any other inventory that is using a custom component, you know, will actually be not turned into a work in progress inventory item. And any item that is using a custom license will be converted into an unknown license. And same as with the version, and if a version is deleted, it will be converted into a unknown version inventory item. And the last item here is we also added the ability to disable custom rules. So there's been a request from one of our customers which says, hey. Before, running a particular scan, I would like to, you know, disable specific rules. And, in addition to having a delete option, we also introduced an option to disable a custom rule so that no one can disable once enabled again, and all the custom rules will now be applicable after that being able to. Some of this, we can go in detail. It's not a lot here, but, no, we we continue to be committed to the new dependency hierarchy. And as I keep saying, you know, this has to be conquered, ecosystem by ecosystem. So so far, we have dependency hierarchy for, Gradle, NPM, and now we're expanding it to Maven as well. So as usual, we will be, you know, we'll be able to see, you know, the current selected inventory item and also the color coded list of items that are, you know, either their parents or their children or know all the transfer dependency items right from the item where you have selected. Okay. And the next item that we had been working on is the ability to apply, you know, license, you know, using the, you know, generative AI. So in some cases where there is, you know, more than one license evidence detected or, you know, code inside cannot determine the actual license, okay, you can use the this, you know, simple button called apply AI license, and it will make a determination based on, you know, public knowledge available way of a given component, okay, and the component version and attach the AI license. So it will be applied on the entire project. And, in case you would want to review this, there's also an advanced search filter available so that you can review those items and then say, hey. You know, this is something that we'd want to re edit, re edit, and then you can change it back to a unknown license or a different license altogether. And, you know, it's not just that. You know, once the license is applied to a component version, it will also be reused in subsequent projects. And, you know, we'd like to inform you that this is only available on demand and, you know, the scan wouldn't automatically apply the license because we wanted to give you, you know, control over, you know, whether you'd want to use this or not. So it's only available on demand by clicking of this button. And, in case you would want to, review those items, you can leverage the advanced search as well. And some of the, items that we've been working on on the SBOM reports in addition to some, you know, special reports are on the cyclone x and SPDX. So we now have the support for SPDX three point o, you know, which is the latest version available in, in the SPDX specification. And for both the report formats, we have made, you know, significant performance improvements for the reports. So we really urge you to go ahead and, you know, grab the latest one from GitHub that is available. You know, I I'll try to find the link now and then share it in the chat. But then, you know, if you do not know, please reach out to our support team. You know, we will be able to help install these new reports, you know, without any problem. And the key difference here being, the as you would understand that not all of our reports are rest API based and, you know, the CycloneDX and SPDX, since they pull a lot of data, they are the use of REST API was proving to be a little performance intensive. So what we had to do was we had to change, you know, these reports to be, you know, database driven. And, the report now generates, like, direct database queries, okay, significantly improving the performance of the reports. And one other item that we have worked on, in this release is, unique vulnerabilities across all sources. So a little background to this is, as an SCA tool, we're going to provide you with as much vulnerability intelligence as we can provide. So in order to do that, what we generally do is we scrape vulnerabilities from, you know, several sources. So these sources are NVD, RubySec, RustSec, GitHub security advisories, OSV dot dev, and, you know, our own research team called, you know, the synchrony advisories. Now what happens, you know, typically is that, you know, even if there is a single component version, so what we'll be noticing is that, you know, some of these, vulnerabilities are available in multiple sources, and they were getting duplicated. So, you know, we went ahead and, looked at this problem and ensured that note, there is no duplication of the same issue across a component version. So there will be, you know, far less, you know, vulnerabilities reported, you know, because, you know, that's a true reflection of your project and then a sperm, and you will be able to focus only on those items that are unique and matter to your project. And, in this course, we also have, you know, given a little more, and especially on the GitHub security advisory. So GitHub security advisories are divided into verified advisories and unverified advisories. And what we've done is when we are locating this information and presenting to the users, so for all advisories coming in from GitHub security advisers, first of all, we only get the, you know, verified advisories. And since these are verified advisories and if there is a mismatch of data between the GitHub security advisory and NVD, we are prioritizing the and, the GitHub security advisory score so that you can take a better decision than, you know, trusting a score that has not been, analyzed or reviewed. At the same time, the raw data is still available in case you would like to go ahead and see what the original score was or what you'll, you know, EPSS rating was and whatnot. You could you're the data is all available for you to take a decision. But, at a high level, we are prioritizing the advisory scores because, you know, these are supposed to be more, you know, defined and, you know, they're verified by a trusted security analyst and by a, you know, industry leading organization. And, we strongly urge, you know, for those who, would have considered, GitHub security advisory size noise. Okay. Feel free to go ahead and reenable them. We'd be able to get a better understanding of the, you know, vulnerabilities across your project. And if you don't, or if you continue to want to keep it disabled or you have already disabled it or you'd want to do not want to see any other sources other than NVD, that's fine as well. And the what NVD vulnerabilities would roll up to the top. Otherwise, the NVD vulnerabilities would be like a child item to the advisories. So in here, what we see, in the, in this dialogue so what you see in this dialogue is if you look at the third item, you would actually see a, an arrow mark. Expanding that, you would actually see the CVE references. So in case you would want to focus only on the CVE IDs and not the advisories, you can go ahead and, you know, disable the advisory, and then you'll be able to see a roll up view of just the CVEs. Alright. So with that, let's, you know, talk about 2026 r one. And, before that, I'd also want to mention that, you know, one of the key item that we have worked on in the r four release is, you know, to say significantly, you know, sizable release with respect to, you know, some of the technical data items. So we had to upgrade our, spring component and, you know, Java and there is Tomcat and there's, you know, Hibernate. So the major components in the application have seen an upgrade, and this should significantly reduce the, you know, security vulnerability footprint on the application. And, you know, we continue to go ahead and, you know, fix those vulnerabilities and then upgrade to the latest components. But, you know, bulk of the, you know, release is comprised of, you know, upgrading to the latest version of the spring. And the latest version of the spring actually mandates us to, move to the latest version of Java. So we moved on to Java 17. And, you know, along with that, we had to also upgrade the Tomcat component. You know, we are now running Tomcat 10. And, you know, we had to upgrade our hibernate component as well. So moving on to twenty twenty six r one. So as usual, we'll continue to work on any security fixes or any critical, you know, field issues. And on the discovery side, you know, we are, we're making an attempt at, you know, CC plus plus discovery from make file and see make files, you know, which are notoriously difficult to understand open source components. And, we've done some discovery of, we've done some analysis of how that can be done, and it proved to be some, invaluable results there. So we will continue to work on that and, add a complete analyzer or a detection technique to ensure that we are able to discover c and c plus plus components from no make files. And the next item would be the direct and transfer support for Rust, Rust ecosystem. So we have support for Rust, you know, the ability to scan, you know, cargo or TOML files. However, the support was limited only to a top level. So we'll be extending this support to, direct and transfer support for both cargo.tamil, and there's also a lock file in place here. So we'll be supporting all the entire ecosystem. And, the last item here is the ability to support, Maven in offline mode. So some of our customers have expressed their interest to run scans in a completely air gapped environment. And, you know, in order to support that, we're, having, you know, the Maven support in offline mode. Sorry. Somebody is meddling with my slides. Okay. Sorry for that. So, so the first one, we have the Gradle support, which, you know, will definitely work in an offline mode because we contact only the internal servers. So for the Maven support to work fully in offline mode as well, so we're going to add that, in twenty twenty six r one where, you know, we'll be running local Maven commands to, you know, get all the dependencies and transfer dependencies and report them. This will also provide, you know, support for, internal registries as well. On the report side, we will have a new report, license obligations report. So I'm gonna talk about this, you know, a little more in detail in the in the next slides. And, you know, talked about the license obligations dialogues, and we will talk about that in a bit. And, you know, some of the items on the mission is category or the ability to export data from global inventory grid. We have been hearing some requests around the hey. I've got this whole bunch of inventory items in global inventory page. However, if I want to export it, you might not have an option. And the more interest is in our own, hey. I want to filter something and, you know, look at all the items and then, you know, export them into a CSV or a spreadsheet. So we're gonna, take a crack at, you know, how we can export this data from our global inventory page and also support, you know, filtering based on the advanced search criteria. And in addition to this, you know, we also are continuing to work on another item, which will be a dedicated page for task. So today, we do have a, task page available, but the task page is available at a particular inventory item level. And, you know, for someone who is coming in and, you know, purely for the sake of, you know, reviewing the task and the approval or rejecting the task, you know, we felt that your dedicated page for task would actually be more, you know, productive. So we're gonna create a page similar to, you know, our global inventory page where you would be able to, view all the tasks and the ability to filter task by, you know, assigned for me or, you know, closed by me and the regular filters that are available in our task. So all of them would be just available in a single page for ease of access and increase of productivity. And, there's been one more item, which is the nested archaue expansion for the s s SCM plug ins or, you know, the git plug in, the profiles plug in, and other, you know, version control system system plug ins that we have. Driven we upload a code base. We do have options of archive expansion. So we could go one level deep or recursive and the level deep of expansion. However, we do not have an archive expansion for SEM plug ins, you know, like a Git, plug in or when you're syncing it from a Git repository or anything, assuming that no the files in a Git repository are already unarchived, but, you know, we use run into cases where most of the customers have, archives available in their code base as is. And, you know, when they get scanned to they would like to have the same archive expansion options presented in as this workbench. So we will have additional options in the version control plugins. I think we'll probably start with, you know, Git plug in, and it will have the extra options to expand it to first level, expand it to end level, and then, sync it to the project and then scan the project. So So those are certain might some items that we'll be working on in twenty twenty six r one. Any questions so far from anyone? Alright. K. So let's move on to a topic which I wanted to, you know, give you a preview of. Okay. Something that we've been working on for twenty twenty six r one, which is, you know, call license obligations. So we do understand, I I think, you know, there's, you know, pretty much your group on license compliance, so I don't probably have to explain, you know, license obligations in detail. But, you know, we all understand that open source components are, you know, free to use. But, at the same time, you know, they have their own obligations to meet as an organization. We all have obligations to meet, you know, when it comes to, you know, open source components. So they grant us permissions, but, you know, they also impose certain obligations that we we must fulfill to remain compliant. So license obligations are, you know, typically classified into, you know, what you can do with a license or, you know, what you really must do with the license or, you know, what you really cannot do with license. So, you know, the can do would act typically be any activities which are explicitly permitted by the license without any additional requirements. Right? And, you know, the must do are typically, like, you know, hey. No. You're using the GPL license component, so you must, you know, disclose the source code, right, of your, application. Or you must include a copyright notice because you are actually using, you know, my open source component. Or in the can do, you know, you can the can do generally tell you, you know, how you can actually use it. I mean, can I use it for commercial purpose? Can I go ahead and modify the source code? Can I redistribute the application in the original format, or can I redistribute in the modified format? Or can I sublicense it? So these are, you know, somewhat some items that typically, you know, people who try to use an open source component really need to know what they can do or what they cannot do with with the open source license. And the cannot do, it is and these are mostly like, hey. You know, you cannot really hold the original other accountable if your application goes into a second, security breach. Right? So bulk of the licenses will fall or will have this particular clause. You know, you, you know, cannot use, you know, my trademark. Right? I mean, you cannot use to, you know, trademark an application, and you are using my open source, you know, component. Or you cannot expect a warranty because, you know, it's free. Okay? Doesn't necessarily mean that you're expecting a warranty from, you know, me as an open source author. Right? And, you know, some cases, you know, you don't don't it also says that you cannot sublicense. Right? You know, you cannot, you know, go ahead and, you know, create your own fork and, you know, sublicense it under a different license. So, you know, when it comes to open source components, you know, our users, you know, deserve the right to, you know, quickly get a snapshot to you exactly like this to understand what they can do, what they can't do, and what they really must do when they are in use of a component of a component. So, you know, this is, you know, what, you know, a lot of you actually try to do with the usage guidance in our text field where you provide your own, you know, text, you know, to say, hey. If you're using this component, you must abide by, you know, these, you know, obligations. Right? So we're trying to simplify that, you know, a little bit more, okay, by providing a view in the UI itself, like this. Right? So what we're going to work on is, you know, this is, you know, development done, but, you know, we'll probably make it a little more pretty. Okay. But, you know, this pretty much, you know, how it will actually look. So what we're gonna try and do is know for every item in an inventory or, you know, for every license that has been selected. So we want to show a view of, what users can do with a particular license and what they cannot do and what they really must do to include to use that particular license. So this is another feature that will come in in twenty twenty six r one so that, you know, users have a snapshot view of, you know, the license usage. Alright. I think, you know, that's pretty much what we have for, you know, today. Any questions anyone would like to bring up? Seeing any questions. It's awfully quiet. I know. Well, I know we we did oh, there. I mean, we could rely on right. How are you? Hey. Good. Do you wanna get oh, there. Nice. Yes. You asked me to show her Steve. Right. So Ria is asking, remind me what version of Java is this on? So we upgraded to Java 17, Ria. So the, you know, the the one that was a minimum requirement for spring and, you know, hopefully, in '26, we'll migrate to Java 21, I guess, which is the most, you know, recent LTS. But for now, we are, look, we are we upgraded to Java 17. So there's a question from Wanda. Are there any plans to expedite the release of updated library versions on the tool? So if you meant the, you know, the data release, you know, one then, I think we are okay, but, you know, feel free to drop a note here or, you know, let reach out to us on where you're seeing a delay in, the release of, you know, component versions or components for that matter. So, you know, we're happy to work with you on figuring out. So I I know that the Maven is slightly slow because they're so huge, but we're looking at, you know, how we can optimize that. But outside of, you know, Maven, we should generally be, you know, on track for a, you know, fortnightly release, you know, every so we generally keep try try to keep the cadence of a fortnightly data release, so we should be able to do that. The Maven, we're working on how to optimize the cycle time because one run of Maven actually takes us, like, a month. So we're trying. to, you know, split and run-in multiple threads to increase the, you know, velocity by which we can publish the Maven component inversions. My cat, there there are some there is a question in the, q and a tab if you can see it. If not, I can read it out. It's from Andres. Yeah. So is there a possibility to import SBOMs is. the question. So yeah. It's been yeah. It's been a any year exactly, Andreas, that we have supported the the ability to import in as well. So, this is embedded in our import dialogue itself. So when you do a project import, you know, you could record project tab, go to summary tab, and then the manage, you know, you would have an option to import import project data. And the import project data, you would have a drop down to select an s p o m file. You can browse for a s p o m file, and, we'll be able to understand the s p o m file and, you know, translate them into components and create inventory items over that. There's another question in the q and a tab, from Ria. So I have a ticket open on this, but looking for advice on getting, curation validation on a scan to persist in new versions of the same project. Teams don't want to have to re clean out the false positives. Yeah. Okay. Yeah. I think I get this. So we are the I think we have been advocating this for a long time that, you know, the best way to maintain versions is to, you know, copy the project. I know, like, for example, you have a project called, you know, let's say, four bar one point o, and then you have scanned the project and you have some inventory items come out. And then you have spent some energy into cleaning out the false positives and, you know, creating, you know, some content which are probably not existing. And you've got the project to a baseline state. And when you move on to the next version of the project, you know, what we typically recommend okay. Not typically, but, you know, highly recommend is make a copy of the same project. So there is a project copy What this would do is this would exactly replicate the x the project, you know, as is. And, when you do is when you do an upload code base or when you try to, you know, sync it to a new branch or an existing branch, you know, which has the latest, you know, files, we would only be picking up the incremental files and sending them for scanning. So, you know, the files that will get scanned or the inventory items that gets generated, okay, are brand new items. So you'd be able to take a look at, you know, what those items are and also clean up the items that, you know, are no longer associated to, you know, f a a file. And then those will be the items coming in from the previous file. So assume you have log four j one point o, you you know, in the old project, but then you have updated your com.xml to log four j 1.1. So what would happen is, you know, the inventory item will continue to be there, but then it will lose a file association because the file no longer exists. So you can easily, you know, look at the files which have a zero associations, which means those are the components that no longer have an associated file, and they can be easily be decided to delete. And then you would have a fresh SPAM, and then you can just review those and generate in a SPAM report. But you will still have to clean the inventory. No. You wouldn't have to clean, I know, the all the, you know, previous false positives if there are any that has come from the previous project. Those will not be there because let's say there were, you know, 10 false positives in version one point after first scan and you have, you know, we went ahead and deleted those 10. Those will not be carried forward, and those will not be recreated again in the second project. There's a question from Wanda. Thanks for following this up, you know, Wanda. So we will actively look at, you know, the Maven, version upgrades, and we will try and see, you know, how we can explain this at least for, you know, components that have versions rather than collecting the entire data as is. And, no. There is a question on the custom versions lack of PURL. So we are also working on, you know, a PURL, enhancement. I'm still figuring out whether how to, create a, you know, custom attribute for, you know, PURLs. So we will be you know, you'll be seeing some PURL enhancements where you'll be able to see the PURL data for, you know, custom entities. At the same time, you'll also be able to edit the URLs, you know, for, you know, edit the URLs, you know, for items that you'd want to, you know, write from the inventory itself. There's a question from Mark on is the SBOM import planned for February release? So SBOM import is already available, Mark, so we can import SBOMs into code insight, as of today. Alright. Tim has a question in the q and a backhand. Alright. There's a question from Timon. Can you give a little more detail on how the apply AI license apply AI feature is implemented, or what or whose server is used in the AI? So thanks, Tim. That's a good question. So, the apply AI license, you know, takes into context, you know, certain values coming in. So it doesn't touch your source code. It doesn't take any input from, you know, your machine. It would, you know, make a call to, you know, the some of the OpenAI services that we'll actually be using rather than any, you know, coding site or, as moments sites API, you know, at this point of time. So we intend to have a switch in there, okay, to, you know, directly make an AI call, okay, or, you know, route it via our servers, okay, in a future release. But for now, what it would do is it would say, let's say, for example, there's a four bar two point o, you know, in bracket in and the, you know, under detection would probably find it, let's say, for example, MIT or BST three claw, clause license. So the AI would make, you know, a determination based on this information only, purely based on this information to say, hey. I bought you know, I got FUWA, and I got one point o. So based on, you know, this information and, you know, the source URL and the component URL, this is all public knowledge. There's no proprietary knowledge available. There's no proprietary knowledge that we'll be gathering here. So the FUBAR, you know, one point o, which has a component URL of this, you know, tell me what could be the right license for this. Right? So and then we'll be, you know, picking up the right license and applying it. So today, we'll be making you know, we're currently leveraging, you know, services, you know, like, you know, Amazon WebRock, you know, for provisioning these API service, AI services. And, in future, we'll have a switch to, you know, go whether routed through, routed to, you know, our own server or, you know, make the call directly depending upon what your governance policy says. If you want more transparency and then, you know, you want to trust, you know, an Amazon service or an Azure service more, okay, you could, you know, take that. Or, you know, you'd want to, you know, route it through our, you know, our servers. We offer better security, so you could do that as well. So it's a question follow-up question from Leon. Project scan, project copy and rescan. So if you make a project copy and rescan, what if changes were made in the previously scanned directories? Is it only going to layer on the components in the newer directories? Yes. So only those files and directories that have been changed will be sent. In fact, not even directly. So the only those files here which have actually been changed. Right? So totally those would actually be sent for rescan. A simple way to test this would be, you know, you take a project, make a copy, and then you just, you know, you know, probably you need an SPAM report and then just do a quick scan. You know, don't change anything and do a quick scan and, you know, it will literally not be any changes. And then you go ahead and change just one file in there. Okay. So it would just scan. The incremental scan would just, you know, scan that one particular file. And, if you want to really see the changes between the previous scan and the scan, no. This year, we have introduced a inventory changes between scans as a feature. So you would leverage that and understand what has changed, you know, from the previous scan. So the first time will actually the the first scan after you have changed your code base should actually tell you what are the new changes that have come in. Yeah. Feel free to ask any follow-up questions on any of these topics, but, you know, love the engagement today. So far, not seeing any, any further questions in in the chat or q and a. Alright. Well, the folks definitely did not disappoint Venkat. They they definitely threw us a bunch of questions, which is fantastic. Okay. Ah, there is there's more here. Go for it. Tim has a question in chat. Yes, Tim. So the SBOM import still requires a call to our, you know, SBOM management solution or the SBOM insights, you know, to complete. We do not have a local module in code inside that processes in SBOM and, translates them into inventory items. Thanks, Gabriel. Okay, Bill. Yeah. I wish I had, Thanksgiving as well, but I don't. So Hey. You you guys have some really great holidays. I'd I prefer, you know, Indian food over some turkey. Alright. Any other questions or comments? Again, I know we threw you guys for a curve ball and appreciate you guys carrying on to the to this, new event here that we created. I think that's all, Venkat. Alright. Well, thanks, everyone. Appreciate you guys, as always, and, I do hope you guys have a great holiday season for those who get to enjoy, like, Thanksgiving and so forth. And then we will see the rest of you guys in 2026. Hope to stay tuned. Alright. Thanks all. Have a good rest of. your, everyone. day. Bye, everyone. Bye bye.