Analyzing (Auditing) Scan Results

FlexNet Code Insight 2020 R1

After you scan your codebase, you can evaluate the results of the scan in the Analysis Workbench. In FlexNet Code Insight terminology, this is called auditing. The goal of an audit is a complete and accurate inventory of third-party code within your products. Sometimes this is referred to as a Bill of Materials (BOM). With this inventory, you will be able do to the following:

Discover and remediate code that is under licenses that put your proprietary source code at risk.
Discover and remediate code with known security vulnerabilities.
Discover and remediate code with no license or under business unfriendly licenses from competitors or malicious sources.
Comply with licenses that have obligations such as providing source code or attribution/credit to authors.
Apply policies based on the license.
Generate reports for your customers or for internal use.

Refer to the FlexNet Code Insight User Roles and Permissions appendix for the project roles (in addition to the Analyst role) required to access the Analysis Workbench and to analyze and act on scan results.

Section Overview

The section provides the following topics to describe how to use the Analysis Workbench:

Opening the Analysis Workbench
The Analysis Workbench Layout
Searching for Codebase Files Based on Name
Searching for Codebase Files Based on Search Criteria
Creating and Editing File Searches
Using the Filter Legend Options to Filter the Codebase
Using the Codebase Files Pane Context Menu
Marking Files as Reviewed
Viewing Details for Licenses Associated with Codebase Files
Using the File Details Tab
Using the Evidence Details Tab
Using the Inventory Details Tab