Video: Software Composition Analysis Office Hours: Code Insight 2026 R1 Release Overview | Duration: 2856s | Summary: Software Composition Analysis Office Hours: Code Insight 2026 R1 Release Overview | Chapters: Welcome and Introduction (5.04s), New Feature Highlights (166.235s), Email Template Improvements (593.185s), Jira Integration Enhancements (983.63s), Dynamic Scanner Support (1354.9s), Q&A Session (2580.5s), File Share Setup (2684.845s), Conclusion and Farewell (2781.025s)
Transcript for "Software Composition Analysis Office Hours: Code Insight 2026 R1 Release Overview": Alright, everyone. Welcome. Welcome. Give us a a few minutes here to get things sorted. Hope everybody's having a great day, and thank you for attending. I think it feels like it's been a while since we last spoken, so I hope the weather has been kind to you wherever you are. Let's see here. Let's give let's go ahead and give folks another minute or so to to join us, probably getting their their coffee to settle in, stay warm, and all that. I see here we've got our slide deck up. So just to let you know that, you know, this event is being recorded. And if you're new here, we do have a chat, so feel free to enter any questions that you may have there in the chat. And when possible, Venkat will go ahead and respond to those questions. And if you have any questions for me, feel free to tag me, and I can help with any questions about the platform or or whatnot. With that said, I will go ahead and hand things off to the man who probably needs no introduction, but I will introduce him anyways, Venkat Donga. Alright. Let's go ahead and bring him on stage. Alright, Venkat. They're all yours. I'll see you in a few. Alrighty. Do you wanna give a couple more minutes, Christine? I think let's give, like, a minute more more for folks to join. Alrighty. Let's get started. Thanks everyone for joining us today. So what do we have for today? We have 2026 r one overview, and we're gonna also talk about our our two plans as well. You know, we have stepping into 2026, there is no change to our release cadence. We continue to be on a quarterly cadence, and we expect a May release. We expect a August release and a November release. So we have our first release in the year in February, which is on February 12. You should be able to upgrade to our latest release, which is 2026 r one. Let's look at what's new in 2026 r one. So we are going to look at almost all of these items in detail. The only thing that we are probably not gonna talk is our support for, you know, MySQL 5.4, which is now included in code insight. So code insight can now seamlessly work with their existing operating systems and also not just MySQL eight point o, but we also can work with the version 5.4. Alright. So let's get started with the first one. The first one is around the automated discovery. As usual, we continue to invest on ensuring that we're able to produce response for all popular ecosystems. So, you know, this particular release has been a busy release with respect to ensuring that we have coverage for some package managers and, you know, some AI models as well. So let's start with the first one. So we have we always had support for Rust. We used we were to we were always reporting top level inventory, but they were request that, you know, we also support the direct and indirect or the transduodencies. So starting this release, we have full support for Rust packages coming in from create short IO. We'll be able to support both the direct dependencies and transfer dependencies, and we'll you construct your SBOM completely. And the second one, you know, to the right is the hugging phase model. So AI has been, you know, everywhere, you know, unless we're all living under a rock. So AI has been, you know, pretty disruptive. So it is no longer just a, you know, a bubble waiting for blast. It has and it's coming really hard at, you know, what everybody is known for best. So and the use of AI models has significantly increased in, you know, development as well. So, you know, that presents as an opportunity and a challenge, which is the ability to detect, you know, what AI models are being used in source code. So we started this journey with the ability to discover Hugging Face models in Python files. So we'll continue looking for more usage patterns in other ecosystems. We know of, you know, JavaScript ecosystem as well. JavaScript also is supported, by the way, in that way, 26 r one. So there is also a spring library where, you know, some of the, yeah, Hugging Face models can actually be used. So depending upon customer feedback, the first feedback was to support on in our python code, which is a very wide you know, widely used ecosystem for AI models. So we went ahead and started scanning your Python code for any Hugging Face models that are being used, and we'll be able to report inventory as a normal inventory. The models as normal inventory at this point of time. But, you know, if there is any interest or any feedback that, hey. We want a different data model for AI models to be used, then we can explore that option as well. And other item is support for c c plus plus. C c plus plus support we all have using Conan at this point of time. Conan is pretty regulated. Conan is pretty standard, it is easy to support, easy to detect, easy to use, easy to maintain, easy to manage. However, you know, there is a lot of legacy code where we do see a lot of make files, CMake, build out make, CMake files dot text and whatnot, which are very tricky to understand and tricky to convert into an open a meaningful open source inventory item. We think, you know, we have, you know, good support for c c plus plus coverage starting twenty twenty six r one using these unorganized or non syntactical files of, you know, may build out sorry, make file or, you see make files dot text files. And the last one is Maven. Obviously, we always had support for Java projects, you know, coming in from Maven. However, there was, you know, request that, hey. We also want to support this in a completely air gapped environment, you know, where the machine doesn't talk to Internet at all. Because for a lot of dependencies, we do hit the main URLs for resolving the versions, resolving the dependencies. So with this particular release, you know, we completely support a an offline support for Maven packages, the ability to scan form dot XMLs, hit internal repositories as well, and then, you know, just get the dependencies as is as declared in the, you know, form dot XMLs along with their transdued dependencies. And, of course, all the full dependency tree would also be displayed. And the next item so this is, you know, one of my, you know, favorite items that I've been talking about, which is a clear view and a very crisp view of what people should be able to do with a open source license. We have an existing functionality for usage guidance where, with the onus is on our users to, you know, translate what an open source license is and the the obligations that people would be able to people should be able to do, you know, with that particular license. What we have done is we have taken that ownership onto ourselves where we can, you know, provide a quick snapshot of what are the open source obligations when you use a even open source license. Like, if you see on the left hand side, if you're using an MIT license so there are three columns in here which clearly tell you what you can do with the license, you know, what you really must be doing with that particular license, and, you know, what you really can't do, you know, if you're using the MIT license. And to the right, you know, one of the copy left examples could be, you GPN two point o only. Okay. Where, you know, you can see that in the must do, you have, you know, disclosed source. Right? So, though, this is, you know, one of the items that we wanted to, you know, share with our users as a very quick snapshot on, you know, what people can do before they actually start introducing any open source code, okay, into their source code. And the next small item that we have worked on, okay, is we also curated our licenses into a small classification called commercial license as well. So if you think about the licenses that we have and some of the components that are available in popular package managers, including Nougat or NPM, we also see some of those components are, you know, free to use for a given usage, but they're not really used you know, free to use in the commercial world. Right? So they need a license to be able to actually use it, okay, if you're actually shipping the product. So we have curated those licenses and categorized them into commercial is equal to true and commercial is equal to false. And we will now be also be able to help you search for those particular components that are coming in from package managers like Nougat or NPM where you can classify them and then say, hey. No. This particular component is prohibited from use because it has a commercial license and is not an open source component. And we have taken a step, okay, to refresh our email template. So we do support a lot of notifications coming in from coding side. We send an email upon scan success. We send an email upon you know, whenever there's a new security vulnerability phone, we send an email when a task is created, and there's so many events out there where, you know, we have email notifications being sent. However, the email notifications, in all candle look a little childish. No. They're not, you know, professional to look at. So what we have done is we have refreshed our email templates to give a more professional look, okay, and also meaningful information coming in in a way that we can consume and take action. So here is, you know, a couple of examples, you know, that I have, okay, which are email templates that we use. One is the first one is for the security vulnerabilities discovered, and the second one is, I think, you know, a new user being created. And, you know, the last one is if an inventory item requires manually, which is coming in from the, you know, task section. And one beauty of this is also that we have, you know, made them customizable. So, you know, those templates as HTML files are available at the installation location. So as a one time activity, if you want to take those and then say, hey. I don't want to use your own branding. I want to use, you you know, know, my own branding, my corporate standards. You are free to do so. You can just, you know, take the HTML file, modify it to your liking, and then we'll just send it to you and save it in the same location. And I don't think this requires a Tomcat restart as well. So, you know, we will be able to honor the new templates in the new, you know, team that you would want to use. We have also introduced some variables, you know, if you want to resolve, you know, some of those variables in the emails. So, you know, look at our documentation for more details on what variables are available. And if there is more appetite to introduce more variables, feel free to let me know, and we are happy to include them as well. The next item we have is we have written up a small report, which gives you, you know, release dates, especially focusing on Maven, you know, to begin with, and we intend to extend this for other packages as well. But if you're primarily a Java project and you'd want to take a look at the releases, release dates of all the component versions that are being used, so we have a small report which is which will tell you the components and their exact release dates, you know, when they're actually released. And we also have a small filter on the top. Now the primary need coming from this is, hey. I do not want to use a component version that is probably any year old or two years old or five years old. So there are filters available in the report itself. It's a simple HTML report where you can just go ahead and select those items, like, you know, show me own items which are older than one year, show me items which are older than two years, or you can select a custom range as well where you can say, hey. You know, show me items which are, like, you know, ten years old. Right? This will help you make a decision on whether you'd want to allow the usage of that particular component portion in coding site in production in your project. And I would also want to, you know, reiterate that now which I'm gonna talk about in our sneak peek as well is that while this particular functionality is for Maven report in to begin with, okay, this will become an 80 functionality in r two where we will be able to show the release dates in, code insight, and we'll also be able to filter with along with the same filters that you see in the report. But in the interim, if someone wants to take a look at this report or wants to install this report, it's available in our GitHub repository. Alright. The next one is around the ability to lock and unlock projects. So we have this functionality, I think, introduced sometime last year where users will be able to lock a project and unlock a project. We made it slightly more convenient here, so we have a easy access button in the project summary page where you can just click on lock project, and the entire thing just changes to, you know, a locked project. Unlike the previous experience where you would have to edit the project and then change the system the project status in order to log the project. And we also expanded this for with an ability for the system administrator to be able to log and unlock the projects. Another nifty functionality in CodingSite '20 26 r one is the ability to export data from the global inventory grid. So we received, you know, some request on, hey. You know, this is good data, but then I'd want to go ahead and export into a CSV file that I can start sharing across. So we have introduced a small button in there where we'll be able to export the data from global inventory page. So this just not just applies to, you know, all the inventory items, but it will also respect the filter. For example, you'd want to only search for those inventory items which are in your project and also having only critical vulnerabilities. You can apply those filter criteria on the inventory page. And then you can click on the export button, which will download the data into a CSV file in the background. So feel free to, you know, use this. But a word of caution is, you know, please do not click on that button without applying a filter. Depending upon your size, it might take a significant amount of time. Alright. So here's another, you know, nifty improvement that we've done. So we now have a very top level page, you know, called the task page. So what you see here are a list of tasks, you know, available in the system or created in the system by users, by the system itself, you know, for those users who want to just look at the task, you know, review them, approve them, or reject them without having to go deep into the inventory items. So we have a small dashboard here, which will tell you all the open task, you know, your open task, and based on their, you know, priority as well. There's some quick filters in there. You know, the you know, you can filter by my task, you know, all task, or do want to see it open task, or do want to see it closed task, and also filter them by priority as well. So for all those customers who are using task for managing your workflows, we request you to give this a shot and then see if you have any feedback. You know, let me know. Alright. Another small improvement here is the ability to, you know, quickly understand whether a given license is in use in a policy or not. So, you know, this is, you know, this has come from a long, you know, pending pain point from our customers who would want to first check whether a given license is already in use in any given policy or not. So it was a painful exercise because I totally get it. It is not easy to skim through, like, 300, 400 licenses and then understand whether that particular license is in use or not in a given policy. So we made its process a little more easier and convenient where you can quickly search for there's a new filter field in the policy page where you can quickly go ahead and test test for a given license, search for a license, and then see whether it has been in used or not. Similarly, the viewers lookup is also now available. So you can just go ahead to you any selected license in the global data global component and license lookup or data library page. Select a given license, and there's an icon in there in the actions button which says, you know, view view policy usage. So if that particular license is in use in any given license, you know, you'll be able to see the details here and here here and here itself so that you can take a decision whether this particular license has to be updated in a policy or not. And it also provides you what kind of action we are taking. Like, for example, you know, in this case, we are selecting MIT, and it is available in the default license policy profile as an approved action. The next one we have is an archive expansion option for Git sync. So we do have Git sync, but the archive expansion options are available only in our upload code base option. So which also is like a, you know, transient state. We'll not be able to store those data. So some of our customers have expressed interest that, you know, some of our Git repositories have archives, and we'd want to expand them during the syncing process so that, you know, I see those files and in analysis of them. Though there are archived files and we're able to scan those archived files, they will not be presented prior to this feature. They'll not be presented in the analysis workbench tree as, you know, expanded files because, you know, we don't really save the archive files, okay, in the in the location that we can actually access in analysis workbench. So with this option, what users will be able to do is that we not only expand them, but, you know, they're present avail they they were available they'll be available in the project code base folder that they they users can actually see and see them in the analysis workbench and, you know, take action on them, view the contents of the files within the archive file as well. So these are the exact same options that we have in our upload code base section. Alrighty. So moving on. The next item, which is, you know, fairly large undertaking that we've taken is the support for Jira dynamic fields. While we do have Jira integration, at this point of time, what we are currently lacking is the ability to support a Jira project, okay, which has heavily which has been heavily customized. So today, we do support Jira, which is which has an out of the box workflow, like, you know, hey. Simple to do in progress are done. But we understand that in real time, you know, users would generally have a lot of customization being done. Hey. Here is my Jira project, and then you have these custom fields being created, which are now mandated for my project. So what happens now is that in the configuration section, the moment you select a given project key in Jira, after you select the connection, of course, you will be presented with all the mandatory fields that are required for you to create a Jira item. So all of those will be presented in the configuration section, and, you know, those items will also be available when you attach this particular instance to a project so that you can go ahead and create a Jira item right from CodeInsight. So the here's a quick screenshot of how the Jira item would look like. So you can go ahead and configure the Jira items Jira con Jira connection, you know, the config in the ALM settings, and then attach the same instance to your projects. I think that we'd also also wait to configure this in the project defaults. I see one question. Think it's in q and a. Laurie has a question. Does the global inventory export option affect core server queue? And can it be canceled if someone does it without a good, you know, filter set? The first question answer the first question is no. It does not affect the core scanner queue. Sorry. The course over queue, Laurie. So it will be done in the background. Today, we do not have an option to cancel this out. And on the way to if we have to provide an option to cancel this, it has to be put in a queue managed by a server. So we did not want to do that. So we went ahead and, you did it as a background action. So it will be it will take some time, but it'll download all the instances. In our experience, it seems to be not very performance intensive because we're only downloading those fields which are really relevant and not all the fields. Like, for instance, we are not let me just go a couple slides back to qual answer this question qualitatively. So what we're doing here is we're exporting the project. We're exporting the inventory name, and we're exporting the, you know, priority and the status and created on, updated on, and we are excluding some columns where we'll have to do complex database joins so that the performance is actually better. Alrighty. Moving on. So let's talk about what's new in coding not not new. Sorry. What we are currently planning for 2026 r two release. So here's a quick overview of what we're trying to do. So one of the big items that we're we have been working on, you know, for a while now, okay, is the dynamic scanner support. I'll talk about this in detail in subsequent slides. And the second item is the ability for users to comment on task. So currently, we do have a single text field, like, the description itself, and the users have to just go ahead and update, you know, their, you know, comments if at all it is going to multiple back and forth in the description field itself. So what we're currently working on is the ability for users to go ahead and add comments for tasks, and that will be shown like any work closest term, like in like, in Jira, you would have seen that all the, you know, tasks are stashed at the bottom with, you in a descending order from based on time. So we will ex you know, we will be exploring a similar option for task view as well where you'll be able to see which user has commented on which task and what are the comments, you know, for a given, you know, task item. The third item is, you know, the an a system an opt an option for users to, you know, upgrade coding site without logging into the file server. This more often, you know, upgrade making the upgrade process a lot more friction free. So what we're currently planning is the ability for users to, you know, say, hey. I'm setting a maintenance window for, you know, code inside. So a a message will be displayed for all users to schedule their work or time their work. The system admin can go ahead and, you take a decision on when they would like to go ahead and upgrade the code inside to a latest version. So we do have quarterly releases, and we do not want, you know, people to, you know, go through a painful upgrade process, you know, to upgrade their instances. So what we're currently looking at is the system admin comes in, drops in a message that, hey. You know, I'm upgrading the system from on this date, this Saturday from, you know, 12PM to 3PM. Right? And banner will be displayed on you know, for all users, and it can be disposed, I guess, that, hey, the system will enter into a maintenance mode for upgrade purposes, okay, on this particular in this particular time frame. And when the time frame hits, you know, the system admin can just log in, okay, and then click on something called as an upgrade button, okay, or something in a butt a button in there. And then the system automatically upgrades to the latest instance available along with updating all the, you know, scanners, the remote scanners, and, you know, bringing the system back up, you know, without having to log in to the file server and going through the painful upgrade process as we have in a manual way. And we'll keep you posted on how we are, you know, progressing on this. I'm a bit about, you know, delivering this in, you know, May our May release, but we'll also have to see if we run it when it is with this. On the SBOM management side, we talked about the short release dates of component versions and the ability to filter by age. So this will be done in our May release where we'll be able to show release dates of most most components. We're also working on those items which we have incorrect information that will be data exercise. So that can be done anytime, but, you know, we're focusing on ensuring that there is a functionality for majority of the components that have the release dates and the ability to filter them by age as well so that you can take a decision whether you'd want to allow those components to be used or not in the SPAM. And we'll also have ECCM fields. Think, you know, this was a silly item why I don't know why we couldn't do this so far. But, you know, we will now have a plain text field for both project and inventory for users to declare and export classification number, you for both project and inventory fields. And on the discovery side, we are looking at Docker file analyzer. So we keep getting this feedback time and again that, you know, in order to scan for a Docker image, especially for those contents available in the Docker image, Docker file itself, you know, we have to use our Docker plug in and look at all the OS components. So and a lot of our users are not really interested in the OS components, and they just want to see what that particular Docker file has or is actually adding into the image itself. So what we'll be doing now is we'll we'll have scanner support for, you know, Docker files where we'll be able to just scan a Docker file and then pass for commands like run command and apt get install command or a yum install command or a DNF, micro DNF. So there's some Linux commands which will help bring open source packages, you know, from some package managers or the Linux package managers into the docker image, and we'll be able to report them, you know, right within Core Insight. On the data side, now we talked about the showing the release dates of component versions. Obviously, we need to collect those as well. So we're on, you we're on a mission to go ahead and collect the release dates of component versions. This data should be available for me when in the upcoming PDN release. And we're also working on how to manage our CVSS v four score. So v four CVSS v four, we've seen that it hasn't seen a lot of an option as we would expect it because it was released late twenty twenty four. But then still, there is a lot of vulnerabilities which are still scored on CVSS 3.1. But then there are items in there which are scored as CVSS v four. So we're going to collect those scores and present to the users. Since the calibration of the scoring itself hasn't changed, we'll be continuing to, you know, show them as, you know, v three slash v four scores because the scores really mean the same. On and as most of other items are, you know, the ability to show file context in analysis workbench. Yes. Laurie has a question. I will quickly take that before we move on because it's contextual to the v four scores. What about CISA ADP? Is there an outlook on that? Yes, Laurie. So that will also be done. So that has no bearing with the v four scores. So we're currently working on this, and we intend to close this by March. So what we'll also be doing is, you know, for everybody's sake, you know, I'll explain what it what the request is is that, you know, sometimes the sometimes Nvidia is so behind their analysis or enrichment exercise that, you there is no real score available from Nvidia because they take a lot of time to analyze the vulnerability and assign a score to it. And CISA starting 2024 or late twenty twenty four, they have really stepped in with their one enrichment efforts where, you know, they would be able to add, you know, the, you know, scoring there. Having a you know, there's a GitHub repo called github.com/c//enrichment. So they are able to enrich the vulnerabilities with their own scoring mechanism. So now what happens is, you know, when they do that, you know, they also have, I think, the mark their scores in the Nvidia vulnerability as something I think it's called a CISA, ADP additional data provider. And they will be able to look at that you know, they'll we see that the vulnerability has a score coming in from CISA. And sometimes, you know, CSA is not there. We also have the CNA. Like, for instance, CNA is generally the CV naming authority. And, you know, if we are coding side, let's say, for example, and we are also in Flexer and Demira are also, you know, CNAs. So we can disclose a vulnerability in coding side if at all there is, you know, coming in native different coding side. And sometimes it also happens that there is a component, and then there's no Nvidia score because Nvidia is behind their enrichment efforts, but then the CNA has published their scores. So what we will also be doing is we will we're currently filtering out some vulnerabilities that are waiting analysis. So, you know, we're removing all such filters, and we will be presenting all vulnerabilities to users wherever we have relevant data. And we will be presenting the scores coming in from CISA ADP as a top priority because, you know, those are supposed to be curated. Okay? And these are supposed to be of much better quality than, you know, anything else. So if the Nvidia score is not available, we will look for the CISA ADP score. The CISA ADP score is available, then we'll go ahead and monitor that. If CISA ADP score is also not available, and if there is a CNS score, we'll go ahead and look at the, you know, CNS score and do that. And if the CSAT score is available, but then there's no CP mapping, you know, what we'll be doing is we'll try to see if that particular compute vulnerabilities available in GHSA, GitHub Security Advisories. GitHub Security Advisories is really awesome. You know, there's a whole army, you know, who is doing analysis of vulnerabilities there. And our experience so far has been that DHS has been a good reliable source for CPE mapping or attaching to a component, you know, especially on the open source front. So even if Nvidia doesn't have a proper CPE mapping, we will look forward availability of the data in GHSA, and we'll be able to present to you a vulnerability that has full accurate details. So that is something that we're working on and not just the CCI ADP, but we'll be looking at other scores as well. We'll be cross mapping it with, you know, GHSA and showing the scores. That should be awesome. Thank you, Laurie. And some of the other items here is, you know, show file context in AWB. I think this is coming in from, you know, some of our deep dive users, you know, where, you know, the there's a lot of deep analysis that is being done. And the request is to essentially say, hey. I we have this we have the file tree file search results tree in analysis workbench. But then what we show there is only those files, you know, that are matching a search criteria. And when we do that, you know, we lose context of, you know, where that file exists and why that file exists in the first place. So we will now be able to show something called a show file context or, you know, show files from here as a menu item, okay, in the tree. And users will be able to see, you know, the full context of the tree and also where the parent folder is and what are the subfolders are. And, you know, this will be available in analysis workbench. And another small item, which is a copy inventory. So some of the users wanted to, you know, have, like, a golden inventory. I know, for lack of better words, as a template inventory, and they want to, you know, copy that inventory every single time and, you know, up keep keep updating the same inventory. So, you know, we will now have an option to quickly copy an inventory into a second item. And the next one is review and review filter analysis workbench. Again, applying a an additional filter on top of the existing results, which is the ability to view, review, and then review filter analysis workbench will also be done. And one of the items I think, you know, I missed here adding is that we'll also take an attempt, you know, this comes with a star, is we'll also attempt to look at how we can clean copy rights. You know, what do you mean by clean copy rights are, you know, is that I mean, we have you some proprietary code in there, and then we have you some proprietary copy rights in there. And we do not want to focus all our energy into our proprietary files, but, you know, it's only those files, you know, which do not have my copy. Right? So we'd want to go ahead and, you know, again, lack of better words, we'd want to go ahead and either claim them or suppress them, you know, as a regular expression or, you know, as a given string that, hey. Do not look for, you know, these files. Do not look for these particular, you know, copyright statements, okay, in the source code or, you know, even if you found them once, you know, mark them in a different group so that, you know, I can focus on open source components and not proprietary items. Yeah. It's pretty much, you know, what we have, you know, as planned for, you know, twenty six r two. If there is a surprise, you know, I'll be happy to share. And I also want to take this opportunity to express, you know, what we are planning to do from this notion called dynamic scanners. So before we talk about, you know, what is, you know, the the notion of a dynamic scanner is, Let's talk about, you know, what is the current state. So in the current state of code insight, what we see is the projects are strictly assigned to a scanner. Right? Once you select once you create a project and you assign a scanner, you know, they are hard bound, you know, forever, you know, unless you delete the project. And what this causes is this causes a lot of inefficiency when, you know, the multiple scanners already already created in my system. But then project b, which is also assigned to scanner one, okay, simply cannot pick up any other scan, you know, from either scanner two or scanner three because it is waiting for project a scan to be done because it's also assigned to scanner one. Right? So, I mean, this is pretty, you know, obvious and trivial that, you know, we have this hardbound assignment for, you know, projects and scanners. And what we'll now be doing is we will be going ahead and, you know, trying to try to leverage all the scanners, you know, capabilities to the fullest extent possible. So what this means is I'll explain the left hand side box in a bit, but, you know, all the projects will actually go through a small orchestrator. You know, it could be simple, you know, service that we intend to write. And, you know, that service will actually test or will actually check for, you know, where, you know, the scanners are free. Right? So imagine this is more like a, you know, a Jenkins scan or a Jenkins build where you have created a, you know, a Wayne Jenkins job, and then you have created a couple of Jenkins agents. And then the job actually runs on any available Jenkins agent. So, you know, the scanners will now work in that fashion where even if the project a is associated to scanner one, if need comes, when project b wants to scan itself and the project b is also suited to scanner one, and if scanner one is busy, it will go ahead and look for whether scanner two or scanner three are free. If either of these scanners are free, we would go ahead and pick up the and take the project and scan them on, you know, scanner two or scanner three. Now while, you know, in theory, this looks, you know, easy, you know, it is not so easy because the core base of project a and project b are currently residing on scanner one and scanner two, you know, respectively. So in order to accomplish, know, you what we want to do with, you know, dynamic scanning, so we're introducing the notion of what we're calling as a file server. So don't get intimidated by, you know, the word called file server, but, you know, it is a fancy name for just a shared drive. So in order for this to effectively work, you know, what we really need is all the code base to actually reside in a single place. You know, let's say, a file server. And the the file server share will actually be mounted onto the scanners when, you know, the scan job is needed. The files physically are present only on the file server, but then the scanner does a simple job of, you know, looking at the mount point and taking those files, scanning them, and then just sending the scan results to project here without copying the files back and forth. So this way, you know, there will not be any change to the notion of how we do how we, you know, perform scans. You know, the scans are still performed locally on the scanners. There's no change to agents, by the way. Know, agents continue to work in a distributed environment, but, you know, we do we we do realize that a lot of our users use, you know, deep scanning for their scanning needs. So and if you want to leverage the multiple scanner support and dynamic scanning, you know, we have to provision a small, you know not small, I would say, you know, a a file share that is capable of storing all the, you know, code bases. Now how does a migration look? So the migration works this way. Let's say, for example, prior to let's say this releases in r two release, which I'm 95% confident that we'll be able to do this. Let's say we are raising this in r two, and then we introduce this notion of file server and dynamic scanning. The current code base of project a let's say project a is assigned to scanner one. The current code base of project a resides in scanner one. What happens is, let's say, scanner one is busy and in '26 r two, we initiate a scan for project a. Project a can as well go ahead and pick either of scanner two or scanner three depending upon availability. And when it does that so what it what it does is it copies the code base from scanner one onto the file share. And this and the scan happens for project a on scanner two as amount point coming in from the file share. And what this actually means is that there is a one time copy of the the project files moving from the scanner one to the file share. So this provides, you know, this provides flexibility both, you know, flexibility and, you know, distributed architecture for, you know, the files that are being to be scanned, the projects, and also the scanners on which the scans are happening. And if there are any questions on this or there's any feedback on this, you know, I would love any feedback on this early on so that, you know, we can, you know, review that and alter any changes required. But if there are any questions on how to, you know, get to this environment to expedite your scans to ensure that you're actually leveraging all your resources optimally, you know, feel free to reach out to me, and then, you know, we can have a constructive call on a constructive discussion on how we can how we can help you, you know, be ready for, you know, dynamic scanning. Though I haven't, you know, planned a slide deck for this, the next increment of this particular item would actually be, you know, having scanners run-in containers. Okay? So the whole idea is to ensure that we leverage the transient nature of the containers and leverage the infrastructure to the fullest, you know, because, you know, these days, infrastructures have, you know, several, you know, infrastructure is so powerful, and we really might not need to dedicate the entire scanner for a single scan. So we might as well, you know, leverage Docker containers as well, you know, for our scanning needs. Again, we are yet to do some benchmarking on it. And if the benchmarks are successful, so we'll go ahead and, you know, go with that approach. Otherwise, we'll stick to dynamic scanning on, you know, dedicated scanners. Some question here. So we have some teams using plug ins. We have some using our sync, and we have and some who upload the code based files via the UI. We need to support. Yes. So this does not really matter, Laurie, because, you know, the base code base the base project folder, you know, changes. The location of the project folder changes. The location of the project folder will now be in the file share. So if you're using a git plug in to scan, to sync the code base, it will now be syncing into the file share. If you're using an upload code base, it will now be uploaded first to the file share. And if you're using an async, you know, again, in the async also, you know, depending upon how you written the code, okay, it will actually go ahead and reside in the project ID folder, which is, again, in the file share. Think that's all I have for today. Is there any questions? You know, we're happy to take questions. Let's see. Give folks another minute or so to to ask any questions they might have. Oh, perfect. Laurie just came up with another one. This is scenario. Project copy is still on. It's scan server. When when the uploaded updated code base is uploaded, where does it go? So when the project copy happens, so in the new notion, in the new paradigm, it will actually be copied onto the file share. And when you update the code base, you know, your code base's root folder will actually be on the file share. So we will ensure to test this scenario for sure, Laurie, but the current design should accommodate this. The same scan server first and move to the file share? No. In my opinion, it will actually be moved to the file share to maintain the paradigm that to establish the new paradigm that, you know, this is my new project root folder. And, subsequently, all new uploads will actually be updated to the same folder. Thanks, Laurie, for so many questions. Is a new file share a new server we would have to set up, and what kind of would it need? So this is a good question. I think, you know, I should have probably, you covered this. There are multiple ways of setting up a file share. So you can set up a brand new server which has, you know, good specifications, or you can convert, you know, one of your, you know, scanners itself, which has, know, you know, probably a good file storage space and, you know, into a file share as well. So all we need is the ability to, you know, have, you know, space on the scan the file server. And, you know, from a specification standpoint, more than anything, very good IO is important here. Why I say that is because we will be mounting the file share onto multiple scanners. So the input output really matters a lot, you know, for performance of the scan. So we urge you to set up servers which are having, you know, obviously, you know, a lot of storage space, which can take all your, you know, code basis. The same time also have, you know, very high IO. We will be, you know, sharing what, you know, are the ideal, you know, specifications for these, you know, for you know, we'll be sharing some scenarios and benchmarks on what would be ideal scenario. But, you know, from a technology standpoint, I think this is what, you know, is primarily required. Maybe give another minute or so to see if folks are typing in any questions. I'm not seeing anything in either the q and a tab or the chat, Venkat. Yep. I think we did. alright. Well, thanks everyone for attending and to Laurie for all the great questions at Venkat for the presentation. The recording will be out later today. So if you wanna go over any additional points or go over the points that Venkat had gone over, you can watch it on demand and, you know, invite folks who want to watch the recording as well. So thanks again all. Have a good rest of your day. Take care. Is everyone bye.