Overview

This page explains details of the Security and License policy violation issues generated by WhiteSource in your repositories. 

Security Issue Details 

Selecting a specific security vulnerability type issue displays its details. The display changes according to the type of library:

NOTE: WhiteSource supports displaying multiple libraries for the same CVE; the libraries will be displayed in the same issue.

Component-based library (e.g., '*.tgz', '*.jar' ): It includes the following information:

Source file-based component: It includes the following information:

License Policy Violation Issue Details

Selecting a specific license policy violation type issue displays its details:

Infrastructure as Code (IaC) Violation Details

Selecting a specific IaC violation type issue displays its details:

NOTE: Only supported in WhiteSource for GitHub.com.