Threatrix Documentation
Threatrix
  • Getting Started
  • Developer Quick Start
  • SecureShip
    • Artifactory Scanning
    • ThreatAgent Scanning
  • Threat Center
    • Creating Account
      • OAuth Login
    • Entity Dashboard
    • User Profile
  • AICertify
    • Reviewing Results
  • codecertify
    • Quick Start
    • Project Summary Tab
    • Components Tab
      • Custom Components
        • Adding
        • Editing
        • Important Notes
      • Header Panel
      • Module Tree Panel
      • Results Panel
        • Card View
        • Risk Graph View
      • Audit History
    • Assets Tab
      • Custom Asset Matches
        • Adding Asset Match
  • securecore
    • Project Dashboard
    • ThreatScan
    • Scan Results
  • Threat Agent
    • Threat Agent Overview
    • Threat Agent - Installation & Scanning
    • Scan Summary Reports
    • Resolving Errors
    • Scanning Container Images
  • Integrations
    • Dependency Managers
      • RENV
    • Build Integrations
      • AWS CodeBuild
      • Azure DevOps
      • Bitbucket Pipeline
      • CircleCI
      • GitHub Action
      • GitLab Pipeline
      • Jenkins Pipeline
    • SCM Integrations
      • GitLab
      • Bitbucket
    • Issue Management
      • Jira
    • Notifications
  • Policy Management
    • Policy Overview
    • Creating Policies
    • Policy Conditions
    • Policy Actions
    • Policy Scopes
  • Administration
    • User Management
    • Organization Settings
      • Organization Knowledge Base
      • Integration
        • Slack Integration
        • Jira Integration
        • Service Keys
    • RBAC
    • Entity Management
    • Okta
      • Okta Org2Org Integration
  • GraphQL API
    • API Overview
  • Resources
    • Dependency Managers
      • PIP
    • Dictionary
    • Licenses
    • Security & Privacy
    • Binary File Support
  • Hybrid / On Premise
    • Getting Started
    • Installation
    • Upgrade
    • Setup
    • Cloud Data Disclosure
    • Troubleshooting
Powered by GitBook
On this page
  • Eligibility
  • Process to add custom Asset match
  • Custom Asset Match List
  • Important Notes

Was this helpful?

  1. codecertify
  2. Assets Tab
  3. Custom Asset Matches

Adding Asset Match

PreviousCustom Asset MatchesNextProject Dashboard

Last updated 3 months ago

Was this helpful?

Eligibility

Custom Asset matches may be added to both unmatched and matched asset artifacts. If you don't agree with an existing match, you can reject the match and add a custom Asset match using the process described below.

Process to add custom Asset match

Asset Custom matches must be added from the Assets screen in CodeCertify or Review screen in AICertfy. Use the 3-dot menu next to the Asset to which you'd like to add your custom match, as shown below

More than one Asset match may be assigned to your source asset

This will display the Add Custom Match dialog

You must enter the URL for the open source asset that contains the matching code

Then select the Check Asset button, in order to continue. This step verifies whether or not the asset is discovered in our Knowledge Base and auto-populates all of the necessary fields.

Threatrix attempts to match the open source asset that you've provided with your source asset to calculate the Percent Match and Percent Copied values. In the case shown below, Threatrix could not find a matching body of code and shows a warning and requests that you complete the Percent Match and Percent Copied values. These values are NOT REQUIRED.

If you wish, you may override the license and/or copyright data provided by Threatrix. The License Search finds licenses in both Threatrix knowledge base and your Organizations private license knowledge base.

Once you're satisfied with the match data, click the Add button to associate the custom Asset match with your source file.

Custom Asset Match List

Your custom Asset matches knowledge base can be found in the Admin Settings under the Assets menu.

Clicking on a match displays the match details dialog

Custom Asset matches may be deleted by clicking the Delete icon next to each match.

Important Notes

  • Deleting a custom Asset match does NOT remove existing matches from current scan results. A new scan is required for changes to be applied to matches.

  • Changes to knowledge base Asset matches will not be reflected in current scan results. This includes changes to licenses and copyrights. A new scan is required for changes to be applied to matches.

  • Changes to Asset artifacts with custom matches will only be reflected in the scan results and not applied to custom Assets in your organizations knowledge base. This includes changes to licenses and copyrights.