Trend Micro Cloud One – Open Source Security by Snyk reporting provides security teams with an accumulated view of all issues across all your projects.
VALUE: The Reports section displays historical and aggregated data about projects, issues, dependencies, and licenses.
The Summary tab provides AppSec teams with visibility into security issues by severity, license issues by severity, and issues over time. The Exposure Window shows elapsed time from when an issue was identified and until it was resolved. The Summary tab also displays activity including test runs, number of projects, new issues, fixed issues, tests preventing issues, and ignored issues.
VALUE: The main dashboard displays a birds-eye view of all your issues (vulnerabilities and licenses), across all your projects.
Because your repository was loaded for this workshop, the Issues over time graph and Exposure window graph will not appear as extensive as the example below. The issues over time will adjust based on remediation of existing issues, and new issues arising.
For more details on the dashboard summary view, please visit Snyk portal
The Issues tab displays all known vulnerability and license discrepancies across your projects with details about each issue, possible remediation steps, and what projects are affected.
VALUE: All issues (vulnerabilities and licenses) across all your projects, including their severity, available remediation if any exists, and more.
Issues can be grouped or ungrouped based on the desired view and required details. Grouping the issues shows an aggregated view and rolls up the number of projects affected. Ungrouping the view shows a record for each project and more columns, including fixable, introduced, status, reachability, and Jira issue, if applicable.
For more details on the Issues tab please visit Snyk portal
From the filtered list, that is now filtered, click on the Issue: Remote Code Execution (RCE) link to read more about this vulnerability and how to remediate it.
Return to the Issues tab using the back button on your browser menu.
Now click on the Dependencies tab.
The Dependencies tab acts as a Bill of Materials for all the dependencies in your projects.
VALUE: The dependency tab provides dependency health for your packages and displays details such as name, version, and which projects currently use the package. The report also gives transitive dependencies and helps identify healthy and deprecated packages.
For more details on the Dependency tab please visit Snyk portal
The Licenses tab displays all licenses used in your project and a summary of all your projects’ dependencies.