FlexNet Code Insight 2019 R1
The settings on Project Defaults tab on the Administration page work in conjunction with a project’s policies to configure the automation of review, remediation, and status notification processes for published inventory. These settings, which are global across all projects but can be overridden at the project level, are used to set up the following:
• | Automatic creation of manual review tasks for inventory items not reviewed by policy during the publication performed as part of a scan. The tasks are automatically assigned to a default legal or security contact (defined at the project level, as described in Edit Project: Review and Remediation Settings Tab). |
• | Automatic creation of remediation tasks and associated external work items for inventory that is rejected either automatically by policy or during manual publication by an analyst. The tasks are automatically assigned to a default engineering contact (defined at the project level, as described in Edit Project: Review and Remediation Settings Tab). |
• | Automatic rejection of published inventory impacted by new vulnerabilities detected in the latest scan or Electronic Update. |
• | The automatic generation of email notifications only (instead of assigned tasks), which are sent to the project owner as alerts concerning the rejected or non-reviewed published inventory items. |
See the following field descriptions for more information.
Section/Field |
Description |
||||||||||||||||||
Automated Review Options |
|||||||||||||||||||
automatically reject inventory items impacted by a new vulnerability that violates your policy |
Determine what action the system should take for published inventory affected by a new security vulnerability discovered during a post-publication scan or Electronic Update. The selected action applies to both non-reviewed and previously approved inventory items on the Project Inventory tab.
If a new vulnerability does not exceed policy thresholds, the current status of the inventory item is not affected.
For information about setting policies that define CVSS-score and severity thresholds used to reject or approve inventory items automatically, see Policies Page and Policy Details Page. For information about associating these policies with a project, see Managing Policy Profiles. |
||||||||||||||||||
Manual Review Options |
|||||||||||||||||||
What should happen if inventory items are not reviewed by policy? |
Determine what action should be triggered for those inventory items that are not affected by policy (and therefore have a Not Reviewed status) during the publication of inventory either as part of a scan or manually by a user:
Information about managing such a task to track the progress of a manual review is found in Creating and Managing Tasks for Project Inventory in the “Using FlexNet Code Insight” chapter.) The value for Select the minimum priority... (described in the next table entry) affects this option. |
||||||||||||||||||
Select the minimum priority to perform the action selected above |
(Enabled when an option other than do nothing is selected for the previous field.) Select the minimum inventory priority (P1, P2, P3, or P4) to which the value for the previous field applies. For example, if the previous field is set to send an email notification to the project owner and minimum priority is set to P3, then the email notification will be sent for only those non-reviewed inventory items with a P1, P2, or P3 priority. No email notification will be sent for P4 inventory items. Note • This option has no effect on the do nothing value. |
||||||||||||||||||
What should happen if inventory items are rejected? |
Determine what action should be triggered for those inventory items that are automatically rejected by policy during the publication of inventory either as part of a scan or manually by a user:
|
See Also
Edit Project: Review and Remediation Settings Tab
Creating Inventory from the Project Inventory Tab
Creating and Viewing External Work Items for a Project Inventory Task
FlexNet Code Insight 2019 R1 Help LibraryMarch 2019 |
Copyright Information | Flexera |