Inventory Details Pane

FlexNet Code Insight 2019 R1

The Inventory Details pane in the Analysis Workbench or on the Project Inventory tab provides details about the inventory, component, and files in the inventory. The pane has the following fields:

Inventory Details pane

Column/Field

Description

Recall

Click to recall (remove) a published inventory item from Inventory Items list if it does not fit the criteria for inclusion. The selected items are removed from the Project Inventory view and are only visible in the Analysis Workbench.

Save

Click to save any changes you have made to the inventory details.

Close

Click to close the Inventory Details pane without saving changes.

Review Status

The status of the inventory item:

Approved—The item is approved for use in the software project.
Not Reviewed—The item has not been reviewed.
Rejected—The item is not approved for use in the software project. Instead, the item needs further review and remediation before being used in the software project.

Alerts

Notifies you whether or not security alerts exist for this item.

Priority

A dropdown list showing the priority level given to this inventory item by the system, with P1 as the highest priority and P4 as the lowest.

You can change the priority for this inventory item by selecting a different priority from the dropdown list and clicking Save. For more information about priorities, see Inventory Priority.

Vulnerabilities

A bar graph showing the count of known vulnerabilities by severity—red (high), orange (medium), yellow (low), or unknown (gray)—for the inventory item. Click the graph to view the list of vulnerabilities and their details.

If no vulnerabilities have been found for the inventory item, the value No is displayed in place of the graph.

Created By

The name of the person or process that created the inventory item.

Confidence

A simple three-segment graph representing the Confidence level (High, Medium, or Low) of the inventory item. The Confidence level is the measure of the strength of the discovery technique used to generate the inventory item. The graph shows three shaded segments for High confidence, two for Medium, and one for Low.

For more information about the Confidence levels, see Inventory Confidence in the “Using FlexNet Code Insight” chapter.

Created On

The date that the inventory item was created.

Updated On

The date that the inventory item was updated. If the item has not been updated since the creation date, the date shown here will be the same as the Created On date.

Name

The name of the inventory item.

Type

The type of finding of this item:

Work in Progress—A set of files with something in common. The work in progress will become a component or license only via manual audit work.
Component—Files from a specific component version with known or unknown license. If this type is selected, the Lookup Component button becomes active, enabling you to select a new component instance for the inventory item.
License Only—Files under a specific license without a known component.

Component

The name of the component. Click to view publicly available information about the component; or click to select a new version (or license) for the inventory item.

License

The name of the license associated with this component. Click to view additional information about the license; or click to select a new license (or version) for the inventory item.

Description

A description of the inventory item. You can update the description as needed.

Url

The URL of the license for this inventory item. You can update the URL as needed.

Disclosed

The Yes or No option indicating whether the third-party component or artifact represented by the inventory item known third-party dependency in your code before it was discovered by the scan or you.

This field is used most often by analysts to denote information about the state of the inventory item.

Usage tab 

Distribution Type

The option indicating how the inventory item is distributed:

Internal—Internally only (such as test framework that might be included in the codebase but is not distributed with the product).
External—Externally with the product, shipped to customers (outside of your organization, including a private cloud deployment at the customer’s site)
Hosted—Hosted in your company’s data center (such as a SAAS application).
Unknown—Unknown distribution type.

Part of Product

The Yes, No, or unknown option indicating whether the item is part of the core product or an infrastructure piece such as a build or test tool. This can affect whether third-party notices are required for this item.

Linking

The option indicating whether the libraries are statically linked (included in the materials), dynamically linked (brought in at runtime), or not linked at all. The Unknown value indicates that linking status is not known.

Linking can affect license priority and obligations.

Modified

The Yes, No, or Unknown option indicating whether a project contributor, such as a developer, has modified the software from its original form. Modification can be an important factor for determining license obligations and distribution requirements that are governed by a specific license.

Encryption

The Yes, No, or Unknown option indicating whether the component provides the encryption capabilities used in the product. Encryption can affect export controls.

Notes tab 

Detection Notes

System notes that specify the automated detection technique that was used to locate the component; license information in the case that the license has changed from one version to another or if the component has multiple licenses; attributes extracted from a POM or manifest file containing project and configuration details.

Audit Notes

Any notes added to the inventory item by the auditor or reviewer, based on findings during the analysis.

As-Found License Text

The actual license text for the license associated with the inventory item; this text is manually added by the analyst during the audit or, in some cases, automatically added by the system based on a high-confidence detection rule. You can enter text in this field for future reference.

Notices Text

The text to be shown in the Notices report for the selected inventory item. For more information about the Notices report, see Generating the Notices Report.

Associated Files tab 

Click this tab to view a list of the files that are part of the inventory for this project. Click the to delete a listed file.