Video: Software Composition Analysis Office Hours: Code Insight 2025 R3 Release Overview | Duration: 3595s | Summary: Software Composition Analysis Office Hours: Code Insight 2025 R3 Release Overview | Chapters: Welcome and Introduction (0s), New Release Overview (7.040120339782874s), New Release Features (109.57015033978288s), Reporting Enhancements (286.4301003397828s), New Features Unveiled (525.1201203397828s), AI-Powered License Detection (1033.2002203397828s), Platform Usage Guidance (3067.980120339783s), Usage Guidance Updates (3185.3400203397828s), License Priority Configuration (3288.885120339783s), Expanding Review Options (3382.850020339783s), Addressing License Concerns (3448.495220339783s), Concluding Remarks (3538.565120339783s)
Transcript for "Software Composition Analysis Office Hours: Code Insight 2025 R3 Release Overview": Alright. Thanks everyone. Thanks for joining, in our August session August edition of, SCA office hours. And, you know, as usual, we are, live with another, quarterly release. So we just released our, you know, code insight 2025R3 release. And, you know, today, we're going to look at, you know, what's new in the release and, you know, and also a nice sneak peek in what we are planning for our next release. So before we go into our major update, so, you know, we just got the rings out. And, as usual, we'll have one more release planned out in, in the November 2025. And here is a friendly reminder for everybody. We will continue, continuing our tradition of, you know, holding up, a user group session for SCA users. This is an open space where, you know, for those who are not aware, there's an open space for all the, you know, users to come together, you know, share their experiences, you know, you know, talk to us, work with us on, you know, what they like, what they don't, what they'd like to see, and, you know, talk about industry topics. And, we have some sessions planned. It's also an open space for you to collaborate with each other, you know, share best practices and all of that. So this time, we're, we switched back to a virtual event. You know, last year, we did a hybrid event. You know, with this time, we switched to a virtual event. And, you know, we have the session planned in September. There is a link in your, doc section. So where you see the chats, messages, and docs, there should be a link for you to register. So we strongly encourage you to register for that so that you can lock your calendars right away so and, you know, have some meaningful conversations with our team. Alright. So let's, you know, without, further ado, let's start talking about, you know, what's currently released. I mean, we have the new release, come out, last week, and, let's look at notes of payload in, in this release. As usual, we have some technical, technical data issues covered and field issues also being, you know, worked upon. The some of the most important items are around the SPOM management. And, as usual, we continue to improve our, detection capabilities on PyPy, Gradle, and .net. So what you're seeing here are on the PyPy front, we have version catalog support and, you know, hierarchy support. Gradle, we have included a note dependency hierarchy support. And on dot net, we have included support for packages dot, you know, properties file. So these these, looks like it's a special file which can hold, you know, the component inversions, you know, outside of its standard CS port file. And now we'll be able to, scan this file as well and report open source inventory. And, now we have a graph representation for dependency hierarchy, and this is something new that we've added this, this release. I'm gonna show you a screenshot of how it actually looks. And, a couple of REST API are SBOM import is completely seamless now. So in case you'd want to start with, you know, a rest API import for, you know, importing your response into coding site, you could do that. And, there's a new API to, you know, fetch all licenses in case you have, you know, licenses and you'd want to, you know, sync them into an external system or, you know, get all the different licenses available, including custom licenses and out of the box licenses. You'll be able to do that using automation. On the infrastructure side, we have a new global rule. I'm gonna talk about this in detail a little more called library manager. And we also have, you know, a project, project locking feature introduced, you know, based on the project status. And, you know, something that has been, on the back of my mind for a really long time is, electronic update optimization with respect to packaging. Some miscellaneous items here are the capturing usage guidance from vulnerabilities when rejected. And let's talk about this in detail. So currently, we have a way to configure policies, to say, hey. Reject a particular item if your vulnerabilities if a component has a vulnerability score of something, you know, five or more or six or more. Or you can say, you know, digit everything that has a vulnerability severity of, you know, higher or more or medium or more. Right? Now there is a usage guidance as well, you know, as to to let users know as to why that particular item got rejected. However, due to the way we process the policies as on today, we if a inventory item or an open source component, you know, it's rejected at this phase, you know, the policy doesn't, you know, process the rest of the licenses and components. And, any further usage guidance on the component usage or the license usage are not captured. So what we're now doing is we'll be able to now, include the usage guidance from both, you know, all three sections in a split of, you know, where if at all the vulnerability gets rejected or approved in a new one section. The next one is, you know, with helping your, automations. Generic plug in options are now included to include, certain options to generate and download reports in your pipelines itself. So this is particularly helpful when when you're setting up your, CSCD pipelines, and you would want to use the agent or the generic plug in and ensure that, not just scanning is done, but the report is also generated in the pipeline process. And, sometimes you might actually want to, you know, stash the report within the pipeline itself. So, if there is anybody who's, you know, using CICD pipelines and are curious to know more about this, well, feel free to reach out to us, and, we're happy to help you understand and, you know, show you know how this actually seamlessly works. A certain improvement to our data library search section. I think last release, you know, introduced a functionality to search by short name. Okay? I think, you know, we should probably have, you know, done it, you know, slightly better. So we received some feedback around, you know, how just a short name search, you know, doesn't work. So we have improved that functionality to search by both short name or long name. So it's an odd criteria there. If you know, if you type in MIT, you know, you would also get everywhere, where both the short name exists or a long name exists. We've added some reports, on our, using our, custom report framework. There's a new s bam HTML report, you know, which includes the usage guidance values. This is a private report at this point of time, but, you know, if there is anybody who's interested in, you know, using this one, you know, we're happy to share with you and, help you install this one. It will soon go public, you know, probably next month or the month later. And the next one is, CycloneDX reports. We have a, you know, a brand new report, you know, CycloneDX report with, certain criteria or attributes added, okay, for the India mandate. So, like, how we have regulations worldwide, there is a, you know, European Union, you know, cyber resiliency act. You know, there is a US executive order. So while we adhere to all of these standards so there is a new standard that has come up in India, okay, which is regulated for all, you know, financial institutions available in India. And, you know, some of the guidelines there and some of the attributes there are slightly, different from, you know, the rest of the world. So, you know, we took a slightly different approach here, and we created a brand new report, you know, of course, on top of the existing report and included these additional values and parameters in the cycle index report. And, you know, last one is the inventory diff report. If, if you recall last release, we have introduced a functionality to view those inventory items that are, you know, difference different from the previous scan. So for incremental scans, when whenever we perform incremental scans, it's critical for us to understand what has changed since the last scan. So we are we'll now be able to see, you know, what are the new items, available, what are the, you know, what are the new items that are introduced in this scan, what are the items that are actually, you know, deleted or inventory items lost, okay, because of probably a component upgrade and all of that. So that functionality is available in, the, product, you know, since r two itself. So we have, you know, built on top of that functionality to include a brand new report that can actually be stashed into your pipelines itself to say without jumping into coding inside, you can actually see, you know, after the scan is done, after the processing is done, we can, you know, stash a HTML file, you know, right into your pipelines and then see that notice there are any new changes from the last time we have we have scanned the project. Alright. So, there's a comment from Laurie that you'd like to check out this form report with usage variance. Absolutely, Laurie. So, you know, I will share you all the details with, you know, how we can, you know, we, get access to this report. Someone has plus one. Can't see who has plus one yet, but I'm hoping it is probably Felix. Alright. So on the Python improvement, so we have, support for Python's version catalog or the TOML file where, you know, there is a special file where the versions are actually explicitly declared. So this is now added into your into our Python support. And, in addition to this, we also added the support for dependency hierarchy. So dependency hierarchy has been on our mind for some time now. And, you know, every release, we're including one ecosystem into it or one or two systems into this, you know, into this area. So last release, I think, we included the concept of, you know, improving, you know, Python's, detection improvements. So this release, we have included the Python dependency hierarchy. We also we we already have the dependency hierarchy for NPM. And, you know, we currently would and this release, we have added dependency hierarchy support for, Python and Gradle. And we're working on dependency hierarchy for, you know, Maven in the upcoming release. Alright. So here's a, new feature that we added, which is, library manager as a new role. So far, the custom entities that get created in the system, they do not have any protection on with respect to access control. Like, anybody in the system could actually go ahead and create a custom component and a custom license, you know, but then that creates a lot of noise without, you know, or, you know, anarchy. But because people can just go ahead and see that, you know, they couldn't just simply find a a complicated MIT license. They could just go ahead and create a custom license, you know, leaving, you know, core users to, you know, understand and figure out who is the actual user who has created this particular license and all of that. So to eliminate, you know, those problems, so what we have done is we introduced a new role called, in library manager. And, the permission to create custom components, custom licenses are available only with the library manager. So we would strongly encourage you to, identify team members on your teams, okay, who have the right, authority to actually create custom entities and add them to this new role, add you know, give them this new permission so that, you know, they'll be able to manage the custom entities. So this will be empty by default, obviously, because it's a new role. And, you know, once a user has been added to this and starting twenty twenty five r three, you know, conventional users or regular users, including, you know, system administrators, will not be able to delete, you know, custom entities, unless they are explicitly added into the library manager. So this gives you more control and, you know, a more clean system to see, you know, who is creating the custom entities and the the ability to delete them as well. So we have when I say delete, we do not have the option to delete a custom component as of now, which is, currently in works. And, while we have the ability to delete licenses, it's on this API and, every day to delete custom licenses coming in our four in the UI. Alright. Now notice that he thanks, Holly. Thanks for the feedback. Alright. So here is one more, you know, feature we've included, which is, primarily towards, you know, in strategy towards how we can archive projects. You know? But but it's just the first step towards, how we can, say a project is completed and ensure that users are not making edits to a project. So this is, based on, a particular status. So there's this project status field, which is available in the edit project. And, the moment, the status changes from, any status to project completed, and the user will be, you know, given this option to, lock the project or not. So what does locking here actually mean? So locking actually means that users will not be able to make edits to the project unless it is unlocked. So, this setting also applies child credits. I don't know if it is very clear because it's not clear to me, but, there is an option to here to include child project as well. It's unchecked by default because we, don't personally think that, you know, the child projects are, you know, closely tied to the audit process, you know, while the parent project is in motion. So we kept it a little separate, but, you know, based on the feedback, we can take, we can, you know, further fine tune this. But at this point of time, it is, you know, they kept separate. If there is an intention to go ahead and lock the project from the parent project itself, you can do that. And once the project is locked, what happens is users will not be able to perform any kind of an edit operation on that except for generating reports. So, there is no new inventory that we can get created. There is no new settings that can actually be changed. There's no scan project. There's no upload code base. A bunch of buttons will actually be disabled, and, all the options would be disabled. And only a project administrator can come back and change it back to, you know, a different status, and then that's when the project. It it's essentially, you know, locking down a project and reopening a project. And, when you log down a project, you go to select, you know, any status, from any status to project completed. And if you want to reopen a project, it would actually be changed from should have to actually change from project completed to a different, you know, project. Would you like to be would like to be able to copy, copy a log to project? This is not done at this point of time, Laurie. You know, we will, you know, take a second second stab at it probably next year. But, until the time, I think you would probably have to briefly unlock it and then copy and then move on to, unlocking it once again. But thanks for the feedback. You know, we will evaluate this once again next year. In the UI, it looks like you can still delete a log project, which seems odd. It is for the reasons of delete. And let me get back to you on this. I do not recall this, but, you know, there is an abnormality or, you know, based on feedback, we will take a look at this. Thanks for, you know, the comment again. Alright. Anything else here? Alright. A bunch of views. Thanks. Thanks, Laurie. Alright. So the next one, is electronic update optimization. Every PDL every electronic update that we release, if you look at the, you know, previous times or the before times, you know, they have been, monumental with respect to time. So, conventionally, our systems are Linux and MySQL, and we do have, you know, customers who are using, you know, Windows SQL Server or Linux SQL Server as a combination. I just presented a couple of options just to show you, you know, the kind of optimization we performed on this. And, these numbers, you know, could actually vary depending on environment. This is our test labs, you know, where, you know, the, you know, the the current times are around eight hours, twenty four minutes for a typical Linux and MySQL scenario, which has been now significantly reduced by, you know, 78% or close to, you know, 78% to just two hours and fourteen minutes. And these are incremental updates. You know, the, you know, the the biweekly updates that continue to run. Okay? You know, hopefully, over a weekend, okay, I'll further optimize to do not ensure that, you know, that we don't spill over into the week and, you know, block any scans. Alright. We talked about an inventory diff report. This is a you know, this is exactly, you know, similar to what we have as a project comparison report. So this is, again, a a new report that is available. This should be publicly available for anybody who's this to integrate them into your CICD pipelines, or, you know, just, you know, view them view the differences in a elaborate report with all the, you know, links and all the, new buttons to see the differences as well. So this trigger port tells you what are the new inventory. What are all the inventories available in the project? At the same time, what are the new inventories that are inventory items that are included in the project, you know, since the last scan, and the inventories which are updated maybe because of file association or, you know, inventory items that are lost because of the component upgrade. All of those items, you know, work all all of those items will be displayed in this particular report. And, you know, if you're using them in a CICD scenario, you know, it would really be helpful for you to not, you know, jump into code inside to find out what these differences are. Okay. So, you know, this has been, you know, you know, this has been on our mind for a long time, but finally, we could actually, you know, make place for this. You know, we finally have a visual representation of, you know, dependency hierarchies. So the current dependency hierarchy that we have, okay, is more of a step by step way to say, hey. You know, a is bringing in b, b is bringing in c, c is bringing in d. And if there are so many items that are coming in, it difficult, it becomes a little difficult to visualize what I'm currently focusing on. So what we've done is, we have included, you know, what we're calling it as a, you know, graph UI view, okay, for, you know, the dependency hierarchy to show a visual representation of why an item in the s form exists in the first place. So if you look at it, there's a, you know, small legend to the top, okay, which says the selected inventory. In this case, in this case, the item in amber, okay, is the selected inventory, and the item in, the items in yellow are the parent inventory of the Amber inventory, which means there are several items which are actually bringing in the, you know, the Amber item. And, you know, the sorry. Let me just correct that. So, you know, there is a direct dependency of the Amber item. The Amber item is actually pulling in, you know, those two, you know, green items, which means, I wish they were more readable, but in the actual product, you know, there is a zoom functionality. You can scroll up to zoom or, you know, use your mouse scroll or use your mouse pad to actually scroll and control plus and minus would actually work. And, these are inter, you know, interactive components. You can just, you know if the tree gets really tricky and especially in the case of an NPM, ecosystem, you can zoom in, you can zoom out, you know, and drag the tree to the left or to the right, and then understand why but it will write them existing as form. And not just that, but, you know, also understand, you know, who else it is actually pulling. You know, why it is existing because it is existing of it. It existing because of its variance, but also, you know, why, what are the other items it's actually pulling in as well. And, you also would be able to see some, you know, transdual dependencies also as to, you know, who are the transdual dependencies of a given, inventory item. And, you know, if there is interest, what we would also want to see is we would like to any users to go ahead and, you know, experience this. And, the next logical iteration, obviously, would be to see items of interest. You know? How can we show you the, you know, not just a complicated, you know, graph UI representation of the entire, dependency hierarchy. But what we want to really show you is, you know, items of interest. Items of interest meaning, show me which items in this, you know, dependency tree are problematic components. Those could be items that are rejected due to, you know, license policy validations, violations, or, you know, items that have, you know, critical vulnerabilities and whatnot. And, again, you know, we'd like to hear some feedback on what you would like to see in the redundancy hierarchy view so that, you know, we can focus on them in an incremental way. It's a question from Wandon. I think that this will present only as a graph on private inventory tab, or we can get this data in any report through API. There is definitely an API, Wandon, to fetch these, but the API calls have to be, like, incremental because we cannot, you know, do, multiple. So there is so if you tap into any particular inventory item, we'll be able to show you who's parent and who is the children. That would only be at a one level. Right? So, you know, because, imagine you're calling the API for the Amber item. So we would not be going, you know, all the way back or all the way in. So but then all the required IDs are there. And if there's a special interest to just get the dependency hierarchy into a separate API, we could do that. Okay. You know, depending on the use case, we could definitely just say, hey. You know, a dependency hierarchy API, which, you know, when you tap onto or when you you pass in the inventory ID as an item, we can get in all the parents and all the children along with the transitive tendencies and, you know, maybe the transitive parents. I don't know. So the parents as well. Okay. And all of them show them in a in a single view. A report is, not available as on today because the report becomes really complex and, you know, the, it requires a complex UI component to visualize this. And, you know, it is very difficult to put that into a, you know, static HTML file, so we would not be able to put that into a report. Because what you're currently seeing here, okay, is one of the 3,000 items, okay, you know, which is, selected, right, in the project. Now if you try to bring in all 3,000 items and get that data into a HTML file, first of all, I don't know if we can really run the underlying, you know, JavaScript component that we actually use. So report probably, you know, is very tricky to achieve. But, you know, if you're curious to, you know, get the data out explicitly on the hierarchy, you could definitely explore an API for this. So thanks for the question, Govindan. That's that's all we had for, the 2025 r three release. I think there's a use case that one is trying to looking for the hierarchy data for vulnerable components or the licenses. Awesome. Thank you. Thanks for that. I think that's exactly what I was trying to say. I think, you know, in the, hopefully, in the next iteration, I don't know if it can actually do that in r four. But, you know, hopefully, in the next iteration of the dependency hierarchy, we will start adding certain, you know, filters in the view itself to see and focus on items that are, you know, of interest. Like, a a simple thing that's running in my mind, okay, is, today we show, you know, representation in a graph UI in a in a graph UI view. But assume there is a, you know, button towards the right to select critical components only, you know, or, you know, license violations only. So those items would be highlighted in probably a different color, you know, for us to identify. And, also, overlay the, you know, notion of, you know, the transitive dependency or, you know, where to actually sit in this form. Because, you know, sometimes, you know, this is like a paradox, you know, obvious to me that, you know, we while we want to show, give visibility onto the entire s one tree, transfer dependencies are something, you know, which we have, you know, very least control over. Right? We cannot really control the transfer dependency. So we want to give that insight for users to say, hey. There is a different component, but you can really not do anything about it because it's actually a transfer dependency, you know, unless you upgrade your, actual component in the as well. K. So here's a sneak peek of, you know, what we're thinking for, you know, 2025 r four release. This is currently being planned for November 2025. And, now the first one would be, you know, technical net and field issues, and we have a, you know, sizable upgrade coming up in r four. Bulk of this work is complete, and, you know, testing is in progress. So, you know, finally taken the, you know, leap and upgraded the spring component in, code inside, you know, from a from an older version which had some vulnerabilities to the latest version of screen that is available. And, this includes a complex upgrade to Tomcat, you know, change to supported GRE as well. So we now have a significant jump from Java eight to Java 17. And, and there's certain other components also that, you know, have undergone upgrade, which I think are, you know, Hibernate as well. So, you know, Java, Tomcat, and Spring, you know, have an upgrade coming up in twenty twenty five r four. So, we'd like users to, you know, go ahead and, you know, experience this. And, I think this will reduce our, you know, vulnerability footprint on, in a coding side significantly. And, you know, hopefully, you know, get a, you know, input performance on the application. On the SPO management side, so, you know, a couple of things that we're, you know, working on is, you know, maybe I can spend some time here on, is, you know, use of AI in coding side. Now there are, you know, teams here who I have spoken to, in, you know, partially about, you know, our plans on leveraging AI for CodeInsight. This is now this would actually now become a reality in twenty twenty five r four. So what are we doing with AI? Probably this would deserve request, don't deserve its own slide, but let me talk to what we are thinking about, okay, with respect to leveraging AI for, you know, code insight or license compliance use cases. Now there are two parts to this. So one is, you know, we have already embraced AI as any other engineering team. So, you know, AI is everywhere. We are, you know, thinking AI first on every single item. However, as far as the customer value is concerned, so there are a couple of items we want to ensure that, you know, AI is in place. A a complex item to solve today is to understand certain, you know, complex license text, you know, which, you know, requires a human intervention to go ahead and figure out, read through the text, and understand that, hey. This is this looks like a b s v three clause. This looks like an MIT clause, like MIT license. So there are several GitHub reports which expose, you know, what kind of license they are. You know? There is a GitHub REST API, you know, which tells me that it is an MIT license. Sure. However, there's also, you know, size of the number of components or size of the number of GitHub reports where, you know, we would not that data of license metadata is not exposed, you know, by the author. And, obviously, the author hasn't exposed it. No. It is not available in the rest API as well. In those cases, it gets very tricky for us to identify, you know, what kind of license it is. So we're leveraging, you know, some AI techniques to ensure that, you know, this particular license text, you know, falls under, you know, this particular, you know, license. And they also go through a manual curation process as well as in, you know, as AI identifies it. No. As in as with any, LM techniques, there will be, you know, scoring done internally to understand what can be a straightforward, you know, AI call out versus what requires for the curation. So that's on the data side. Now, you know, once the data is, you know, being passed off into code insight, again, you know, we, there are a couple of, you know, thought processes, and I'm happy to hear any feedback. So one, we update existing mappings of the components, licenses with the AI, you know, detector licenses. I'm not calling them AI generated. These are not AI generated. These are AI detector licenses. You know, they'll be passed they will not be passed off as, you know, detector licenses by us. So it will be, like, you know, AI, you know, detector licenses, and it will have a special flag on its own. On the product side, you know, there are a couple of items, you know, still. You know, even if you're not able to identify, you know, some of the license text, you know, we will still have items, you know, in existing projects or new projects where, you know, the license mapping is null. So in those cases as well, you know, we'd want to, give some provision to users to, you know, go ahead and, you know, take the help of AI. Right? So there would be a button available in the product. Okay? When clicked on, okay, it would, you know, suggest you to pick up a license, depending upon what AI thinks, okay, is the right license to it, based on, you know, the kind of instructions that we give it to it. So users have the choice to pick, you know, those licenses upon curation. And, over a period of time, we'll also want to automate this process in the scan process itself. But, again, you know, all of this would be a setting, and we would want users to be very deliberate about this, whether we want to, you know, trust this information or not. And, you know, and then, you know, take, take the, you know, take the decision on behalf of the, you know, user. And I even after this entire process is being done, you know, we are we want to ensure that, we want to ensure that users have the option to go ahead and review, you know, what the existing data library has been has been has selected as selected license and versus, you know, how AI has suggested. Like, for example, there are, you know, 10 inventory items upon which, 10 inventory items, you know, for which AI has chosen the license. We'd want to ensure that, you know, we want to ensure that the users have an option to review it. So it'll also be followed up with an advanced search, you know, where, you know, you can search for, hey. Show me only those items which are curated by AI, and you have the option to review them and then override the results if required. So this is, you know, roughly what we are thinking about at this point of time on, you know, AI suggestions for licenses. So the data work is, you know, mostly complete. So we have been working on, you know, a mix of, you know, both, LLMs that are available publicly, like, you know, some OpenAI models and also, using some of our existing data to train, data to train, you know, a model which can identify the licenses. So, you know, the you know, that answers the question, I think, you know, which Dan was asking. Can you walk through how AI is suggesting the license? There are two parts to this stand. So one is, how the license text, okay, is understood by the LLM on which license it is. So that's a mix of, you know, using both OpenAI techniques and also, you know, based on existing data that we have, you know, that, you know, we're training our, you know, model. And the next one, okay, is okay. Hey, Ria. Hi. And the next one is, you know, which models is being used and which models have been used, and is there any lag involved? So this would be, you know, I'm guessing it is, I do not know the thing, but I can talk get this detail back to you then. But, you know, this is a a as far as I know, this is an open AI, you know, model, and you'd say, you know, it's a rack query, but a curated query that we'll actually be sending it to in the, yeah, in to the LLM to, you know, understand what kind of license it is under. And the the, you know, the context that is given to that, okay, is most critical here, you know, where we provide, you know, all the the component name, URL version, and everything, and any previous history of, you know, a selected license in the product as well. So all of that input would be actually provided to, you know, the element to to understand whether this falls under a particular license or not. Does that answer the question, Priya? This is a topic that is close to my heart, and then I'm happy to, you know, brainstorm, take feedback and, you know, fine tune this further, okay, if there are any questions or if there is any feedback. Right? So, Ria, if you have any follow-up questions, feel free to just unmute and, you know, let, you know, let us know. We can, you know, happy to we can engage. And, sure. Absolutely. So, yes, there's a lot of questions, and, we can probably cover them in, in a separate meeting. And the next one is, you know, dependency hierarchy support for Maven. You know, we're continuing our journey. We've done we now have dependency support for, you know, NPM, Python, and Gradle. And we'd want to support, extended support for, you know, Maven build ecosystem as well. And, you know, hopefully, in the next release, we'll also include, you know, NuGet and the RubyGems as well. On the report side, I don't think I've covered it in the r three release or maybe we did not do because, you know, reports are reports are are not really tied to release. But, the performance of both the SPDX and, you know, CycloneDX reports, okay, will be significantly improved, because there's tons of data that these reports actually require. And we have switched to, not calling rest APIs for these specific reports, but, you know, delay on DirectDB calls for, you know, these reports. The CycloneDX report work is already complete, and the the SPDX report work would, know, soon be complete and be available because it's not really tied to a release. And, users should be able to, you know, generate, you know, the reports, you know, significantly faster. The second is report, we saw an optimization of around 80% when we switched from, you know, REST API to just DB calls directly. And, we're currently also investigating how we can add support for the SPDX three point o. So far, we support the SPDX 2.3, standard. And, you know, three point o is developing. I think it is in three point o point, x, you know, this point two or point three version. And, we'd want to include this support for, in a coding site as well. And depending on the schema changes, we want to see, you know, how much of the schema changes are different from 2.3. And, you know, we will probably include this as a separate report in a separate repo available in our GitHub repo. There's a question. I may have missed it, but did you cover the SBOM with guidance? It was not an explicit one, but I think I have a sample for it, Dan. I can, you know, probably show that. And, you know, after this slide, I will probably, you know, switch to a screen share. And, you know, if I have the report handy with me, I will share my screen on how the report looks like, you know, the SBOM report with usage guidance. And, a few other items in, we're working on in 24 is, unique vulnerabilities across all sources. So this is, you know, another thing that, is, that I'm working closely with engineering team is, you know, how we can show unique vulnerabilities, you know, given that a a CV can exist, say GitHub security advisory can exist, but both of them reference to the same underlying vulnerability. So rather than showing it showing them as two different vulnerabilities across two different sources, what we are currently doing is we have, you know, kind of reconcile them into a single, you know, line item so that, you know, you have, you know, one item to worry about and, you know, one curated source to look at rather than, you know, two disjunct, you know, sources that give you, you know, the same information. So, in this case, we will show the data coming in from, you know, both of the advisories. You know, in case of, you know, GitHub security advisory and RubySec, you know, we'll also show you the underlying CVE. However, we'll also show the CVSS score from, you know, both of them. But, you know, some additional parameters, you know, we would want to go ahead and, you know, prefer the for the computation purpose of, you know, whether something is really critical, something is not. Okay? Wherever we have an advisory model, we'd want to, you know, prefer the advisory model. So we need to give a small example. Let's say there is, you know, GHSA one, okay, which has a reference to CVE one. Right? The CVE one might have a score of, you know, nine, you know, but the GHSA, which is a reviewed and curated security advisory, which talks about the same underlying vulnerability but has a lower score, which means, you know, a proper security team has, you know, curated this and said it's not as severe as in meetings. So, you know, we are, you know, redefining the score to seven. So if you open up the vulnerability dialogue, you'll be able to see both the scores so that you understand what is the difference between, you know, this and this. But for computational purposes, you know, we'll be taking in the curated curated scores, you know, from GitHub security advisory and not the CVE. So this is one change, you know, that would, you know, start in twenty twenty five r four, you know, with, you know, two primary reasons. So one is to ensure that, you know, there's no duplication of vulnerabilities, and second is to ensure that we are showing you meaningful, actionable information rather than, you know, just showing you raw data coming in from NVD. And, the next item, I think, you know, this is, your feedback from, you know, Laurie's team. You know, the usage guidance values, you know, especially for the hosted one, you know, this particular use case where, you know, the the open source component can actually be used, you know, as a hosted service. Okay? But, you know, it could actually be, you know, as a posted service only for internal use, but not external use. So, you know, to cover this particular use case, we are expanding the, you know, usage guidance usage guidance values to cover for, you know, an existing value like post read any. Okay? Or, you know, post it for external use or post it for internal use. The next one is filters for vulnerability suppression. You know, vulnerability suppression, has been, you know, one of the, you know, biggest success for people who have been using our vulnerability features, especially when they know that this particular item is like a two and is it it doesn't impact our project at all. However, no, there are certain, you know, friction points, you know, in the, you know, vulnerability, you know, post suppression phase, okay, where they'd want to see, you know, which vulnerability has been suppressed and whatnot. So in the vulnerability suppression page, in the data library, we'll be adding additional filters for, you know, users to go ahead and view their suppressed vulnerabilities with more ease. So we'll have options to filter by project, vulnerability, and component. And, we're also looking at ability to disable, you know, custom detection rules. This feedback has come from one of our customers where, you know, we'd want to, you know, go ahead and while the scan before the scan process, we'd want to disable, you know, some specific custom rules. Today, I think there's an option to only delete, custom detection rules. So what we'll be doing is we'll also be including, the ability to disable a custom detection rule and also, you know, hopefully, an option to do it in a bulk way as well. You you select multiple, custom detection rules and, select, you know, disable or delete for that matter. And, on the infrastructure side, you know, the first one is content investigation. You know, it's not a, you know, complete commit commit, but I'm hopeful that we'll be able to do this. We have our nested on, you know, unarchive support. And when they say nested archive support, you know, it's essentially, you know, if you have an archive file in the upload code base, you have an option to go ahead and select whether you'd want to expand and do in the upload phase. However, if there is, you know, an archive file available in the repo itself, like a git report, a proposed, or whatnot, and if it is a zip of zips and whatnot, we do not perform any archival process at that point of time. And the files, you know, that are that go through scan, though the scan process can, you know, expand it during the scan process. You know, in the analysis workbench, we still just see a zip or a RGC. So So there's a request to, you know, see how we can actually expand, you know, these files, you know, during the git sync or a buffer sync or any version control sync. We'll start with git sync. You know, hopefully, it is not specific to, you know, each version control system. But, you know, we're trying to accomplish, if there is a ZIP file available in the repository, how we can expand that part. The next one is, CVSS v four score collection. This also, again, you know, Venkat's wish list. You know, hopefully, we'll be able to get to it, you know, towards, since it's a data item, this is not tied to November. But, hopefully, by December, we'll be able to start collecting, you know, v four scores as well. We're now seeing that, you know, the vulnerabilities that are being curated in 2025, you know, there's a small spike in, collection other people reporting a v four score instead of a v three score. And, the last item that will be available is, the ability to delete, you know, custom components and licenses. So we have the option to delete licenses via REST API today. Again, no. We're not talking about, out of the box licenses. We're talking about only custom licenses and custom components. The custom license deletion is available via REST API, and, it will soon be available in UI as well. And, the custom component deletion will be included in twenty twenty five r four release. And, every component like, for example, I have created a custom component, and, there are 10 inventory items that are, you know, using the custom component. So when the library manager that is when the library manager's phone is key, and the library manager comes in and tries to delete a custom component, the those inventory items which are using these custom components will be changed to work in progress. So this feature is also being actively worked upon for our, you know, last lease of the year. If you can, you know, post any questions in the chat or, you know, just unmute and, you know, talk. In the meanwhile, I'll try to, you know, bring up the report, that, Henal Dan was talking about. And if I can show that. I'm just, can we just do a screen share for our customer? Should allow you to do screen share. It's, stop sharing for a second. Yeah. Can yeah. I can see it. Can you Yeah. Got it. Yep. I I got it. Cool. I think it is from what So this is the report I was talking about where, you know, we have a newest warm report with usage guidance. And, you know, in earlier, the the we have a standard report available now today, which is an SVM report, in the HTML format, and it's the same report in HTML format. This the difference between, you know, that report and this report is, the existing report had, you know, p URL as a single column. That report is still there. It hasn't gone away. We have, you know, made a fork of the same report and, removed the p URL column and added two columns here, which is, approval status and usage text. This is a an older version of the report. You know, this column is now color coded with the approval status. So, you know, the essentially, the change is addition of these three columns, certainly, which is the approval status, the usage text, and whether a particular component has vulnerabilities or not. Dan's asking a question. Could we get the URLs added to the h bam reports? So as I said, Dan, so we have an existing report. Let me see if I can bring that up. So this is the existing report. So, you know, this report is already available. So we have an SBOM report with component version license and, you know, the p URL, you know, column available. And, you know, for a very specific need, what we did was we, you know, put inspiration from the same report and replace the p URL column with, you know, two more columns or two more columns. The approval, status, usage, text, and vulnerabilities. If there is interest, just add p URL column in here as well. So, you know, feel free to let us know, you know, you know, there's a case or this, you know, document. Yes. Okay. Fine. That's good enough. No case required. We can include, you know, URL in the same report. There's a question from Laurie. Custom content deletion. Would be nice to have a query first to see if it is in use anywhere before we delete it. There would be a warning, Laurie, when we implement that, before deletion, that there will definitely be an indication that, you know, this component or this custom entity is actually in use somewhere in the system. But it will not be able to show all items that are using that particular item in a given view. Hopefully, in a future release. But, you know, we would definitely warn the user that, you know, this item is in use, okay, you know, somewhere in the system. But if you would like to, you know, understand where it is, I'm hoping that you can actually use, the, you know, global inventory view, you know, the global inventory view to do a, you know, quick advance search to find out, you know, whether, you know, the license is in being used somewhere or the component is in being used somewhere and understand where the usage is. But there will definitely be a warning where, you know, we'd be you know, before, you know, doing a hard delete, we'll be able to show what the where it is in being used or not. Global interview does not use the ID. We can fix that. Yeah. That's that's good feedback. So, yeah, I think I see what you're saying. So you're looking for, you know, items, you know, specifically not just by the name, okay, but also by, you know, the either the license ID or, you know, this one. I think what we could do is we could expand, you know, this, you know, license name to, you know, select license. You know? Like, for example, you know, a specific license as well rather than just say, you know, arbitrary text here. We could go ahead and, you know, select have the option to, you know, choose a specific license as well. And, also, you know, choose, a different a component filter as well. You know, that's also, you know, something that we could do. That's good feedback, Lord. Thank you. Okay. I'm stopping screen sharing. Could you see how we can do that? Yeah. Thank you much for engaging today. And if there are any other questions, you know, feel free to, again, put it in the chat. And we request everybody who has joined today to, you know, please register for the user group. You know, the link's available in the in the dark section, and it's also available in the community. I don't know. Probably have bombarded you with, you know, multiple box of communication already. I think there's an email also that went to stream. Yeah. Absolutely. That that that's been going out, but, obviously, we also don't wanna spam everybody. So, and I think so, Dan, Ria there has a a request for the usage guidance screen share again. Oh, yeah. Thank you. Yeah. Can you, stop, the slides, and the slides real quick? Yes, Dan. This is enough. I think this has some filters to it. I don't know. Okay. This is okay. These are not filters, but they actually jump into the project. Yep. And then with this new platform, I think you guys might be able to see a little magnifying glass. So if you wanna take a closer look, you can click the little zoom button there. Yeah. It's very fancy. No. That's me. I don't know if it's reflecting for everybody. I'm sorry. No. No. It's not Venkat. Yeah. I'm not seeing a change. So Oh, alright. No tools. No. Alright. Any any other questions, comments, requests? Alright. We're we're waiting for folks. Just a reminder for those who joined a little late. Yeah. This is our new platform, but we are still same format as before. This event has been recorded. It will be sent out, as soon as it's, as soon as it's available. Okay. One two more requests. Is it just license guidance or one? It's usage guidance essentially, Dan. You know, so whatever is being, captured from the inventory items usage text, you know, it will be shown. This is a usage guidance from the inventory item. And, if you recall in the road map, we talked about, how we will now be able to capture both of them in case of a rejected inventory. Let's say there is a, you know, an item which has, a vulnerability, and with this, you know, this particular item, let's say, this particular item has a vulnerability and the usage guidance of the vulnerability as well, okay, in the usage guidance. And, you know, this one, LGBL two point o, even if it is approved. Right? So though the policy says, you know, reject a particular item as because of vulnerabilities, you know, but then, we also have a license policy that covers and adds the license usage text. You know, both of them will be appended to each other, and you'll be able to see the new usage guidance in combination. And the inventory items usage guidance, you know, holistically will just be populated in the report. So I'm so happy this report has, you know, a lot of attention. You know, you know, we we did this like a, hey. This is a, you know, special ask, and it's a trivial report. But then, I'm so happy that users have more questions on this report. Thanks, Dan. Is it possible to change the license priority based on product delivery use case? For SaaS products, a GPL should be p one, but, while GPL might not be a p one issue. So the way we try to do this one then is via the usage guidance. I think, you know, I can chat with you more. But at this point of time, there's no, specific change to license priority because, the priority field the license priority field is a a license attribute and not a part of project attribute. And, you know, the policy definition can be configured to approve or reject an inventory item based upon the usage guidance. You know? I I think this is what we are talking about in the, you know, post thread purposes. Right? So then the usage guidance, you can go ahead and set it to, you know, hosted or internal use. And in those cases, you can configure your policy to say, you know, AGPL, okay, is, you know, for SaaS projects, AGPL should be p one. So, you know, for AGPL and if the the usage guidance is hosted, you know, it should be rejected. Right? So I will probably talk to you more, on, you know, how you can configure, you know, policies for approval and injection, including the usage guidance values, if that is a little unclear on. I'd like to have more than just check question or access options in reviewing. Only three options is pretty limiting. Okay. So you're talking, Dan, primarily about the inventory review status. Right? So we have only approved, rejected, and, you know, not reviewed. Okay. We could we could explore that, you know, while it is not a priority now, but, you know, I can work with you on how we would like to see this. I think, I think we had, some feedback in the past from, in Laurie's team as well, because Laurie's in the meeting, as to how we can have, you know, the, you know, different statuses for, you know, different personas, you know, for license compliance and, you know, for security personnel. And, you know, we could explore an option where, you know, we can expand the data model of the, you know, review status to, you know, slightly more, you know, items and, you know, also explore options of, you know, how we can expand it to, you know, a second level review as well. Sure. One precaution as opposed to not approval, it will be helpful. Okay? Right. So one that has no comment, approval revision is clear. The strong copy left on the summary UI sometimes, is concerning for the management folks. Right. So, let me understand this a little more, Ghandan. I'll probably engage with you. Okay? I think I understand what you're saying. Okay? Rather than doing it in inventory item level, you'd want to understand you want to say, you know, this particular project is a SaaS project, and I'd want to treat, you know, AGPL differently in this project compared to a different project, you know, which is probably, you know, hosted as on prem. I think, you know, that's what you're referring to, and, you know, we can explore ways as to how we can actually do that. Good. I know we're over on time, Ben Kat. Great. A lot of, feedback and and comments here, so that's good to see. Yeah. All good. Alright. So it looks like we'll we'll probably wrap it up here. It looks like Venkat has a lot of work and follow-up to to do. Thank you all for attending. Hopefully, the the new platform has worked out for everybody here. And I'll get that recording out to all of you. And please don't forget to register for user group if you if you haven't already. Again, the link is under the stocks tab, and I'm sure you'll get another email shortly with more information about what we're actually gonna be covering, during the event. Until then, we'll see you guys all, and, have a good rest of your day. Thanks again. Bye, everyone. Thanks, everyone. Bye bye.