Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

Table of Contents

Overview

...

  1. Start Visual Studio.

  2. From the menu bar, select Extensions > Manage Extensions. The Manage Extensions screen is displayed.

  3. In the Manage Extensions screen, open the Online section from the sidebar and click Visual Studio Marketplace.

  4. In the Search area on the right, enter whitesource and press Enter.

  5. Select the WhiteSource Advise extension, and click Download.  

  6. Click Close and restart Visual Studio so that the extension can be installed.

Activating WhiteSource Advise

...

NOTE: If you check Remember license key, the activation credentials will be stored for later use. Once stored, the WhiteSource Advise activation credentials will be used for all projects.

Scanning for Security Vulnerabilities

Automatically Scanning Projects

WhiteSource automatically scans your solution and/or its projects after you perform a Build or Rebuild action on those solutions/projects.

If you do not want WhiteSource Advise to automatically scan your solution/project, you can disable this functionality.

...

Configuring WhiteSource Advise

Info

Changes made to the WhiteSource settings will only apply after running the next scan.

To configure WhiteSource Advise, do as follows:

  1. From the menu bar, click Extensions > WhiteSource > Options. The Options screen is displayed.

  2. Set the Automatically Scan after Build or Rebuild action parameter to False, click OK.

Manually Scanning Projects 

...

  1. Review the options and modify if necessary. See here for a list of all options.

  2. Click OK.

Options Table

Option

Description

Default Setting

Automatically scan after build or rebuild action

When enabled, WhiteSource will trigger a scan after a Build or Rebuild action is performed on any of your solutions/projects.

Selected (checked)

Only show issues for direct dependencies

When enabled, WhiteSource Advise will only return vulnerabilities for direct dependencies defined in your dependency file.

Unselected (not checked)

Minimum vulnerability severity level

Alert only on detected vulnerabilities satisfying a Low/Medium/High minimum severity level.

  • Low - Vulnerability alerts for all severities (Low, Medium, High) are displayed.

  • Medium- Vulnerability alerts only for Medium or High severities are displayed.

  • High - Vulnerability alerts only for High severities are displayed.

Low

Scanning for Security Vulnerabilities

To scan for security vulnerabilities, do one of the following:

  • Scanning a Solution

  • Scanning Projects

Scanning a Solution

To manually scan a solution, do any of the following:

  • From the menu bar, click Extensions > WhiteSource > Scan Solution with WhiteSource Advise

  • From the Solution Explorer pane, right-click the solution and from the context menu, click Scan Solution with WhiteSource Advise 

Scanning Projects

To manually scan one or more projects, do as follows:

...

  1. From the menu bar, select Extensions > Manage Extensions. The Manage Extensions screen is displayed.

  2. In the Manage Extensions screen, open the Updates section from the sidebar and click Visual Studio Marketplace.

  3. Select the WhiteSource Advise extension, and click Update.  
    NOTE: If the WhiteSource Advise extension is not displayed, a new version is not available.

  4. Click Close and restart Visual Studio so that the extension can be updated.

Uninstalling WhiteSource Advise 

...

  1. From the menu bar, select Extensions > Manage Extensions. The Manage Extensions screen is displayed.

  2. In the Manage Extensions screen, open the Installed section from the sidebar and click Visual Studio Marketplace.

  3. In the Search area on the right, enter whitesource and press Enter.

  4. Select the WhiteSource Advise extension, and click Uninstall.

  5. In the popup, click Yes.

  6. Click Close and restart Visual Studio so that the extension can be uninstalled.