Last updated
The Open Source Risks (SCA) can be accesed by selecting the SCA option under the Risks tab . This tab provides a comprehensive view of all the security issues of the dependencies.
You can reach the Open Source SCA statistics either by selecting Risk selecting the top-right statistics tab of the SCA page.
Secrets' Statistics view shows:
Charts for # of issues by severity, by type and by type & severity
A table with the issues (as well as a filter for the table)

You can use filters to select specific issues:
By Funnel Phase (see Prioritization Funnels )
By Severity
By Issue type
By Dependency type (direct or indirect)
By Reachability (see reachability)
By Fixability (see fixability)
By Project (pattern)
By Issue status (open, confirmed, muted, etc)
By Tag
Clicking on an issue with public vulnerabilities will open a slide with detailed information about the CVE.

Vulnerabilities also show information about Fixability. Please see Fixability for further details.
The Reachability Analysis tab provides detailed information on the call paths leading to the component's vulnerable method(s).

Please visit the Reachability documentation for further information.
Clicking on a component with malware detected by Xygeni will open a slide with details.
The Summary tab shows detailed information about the component:
Explanation
Component name
Location where defined
Description

The Malware Evidence tab provides detailed information about the detected code evidence.

Last updated

