# Card View

Component scan results are grouped by the module and dependency manager from which they originated. The name of the module and path to the dependcy file are shown at the top of each grouping.

<figure><img src="https://3093892275-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MbsieSiu0D66DBFP4uh%2Fuploads%2FnasvmiiPCuJAEOe9zGEJ%2Fimage.png?alt=media&#x26;token=0ab6c74f-d262-4ce0-97ba-0d2008ffcf07" alt=""><figcaption></figcaption></figure>

## Card Anatomy

### Component name & version

The components name and version are derived from our knowledge base data as part of our comprehensive data ingestion process.

<figure><img src="https://3093892275-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MbsieSiu0D66DBFP4uh%2Fuploads%2Fbt8ACJ31pAyWpMqIuotk%2Fimage.png?alt=media&#x26;token=4625a637-b3f9-4a50-96a1-4c610055fcab" alt=""><figcaption></figcaption></figure>

You can navigate to the component ecosystems provenance data by clicking on the provenance link shown below. Whenever possible, we make available the oriing or our data for the purposes of transparency and trust with our users.&#x20;

In the example below, the artifact absl-py originated from the Python ecosystem as evident by the pyton logo in the lower left corner of the image. Clicking the provenance icon will open a new tab to provenance of the exact version of this component. This allows users to quickly verify the integrity of our data, such as the Apache 2.0 license.&#x20;

<figure><img src="https://3093892275-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MbsieSiu0D66DBFP4uh%2Fuploads%2FBSvuoRONNcrURFaTiAip%2Fimage.png?alt=media&#x26;token=33187db5-594b-49b5-8c17-e52d763ac602" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3093892275-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MbsieSiu0D66DBFP4uh%2Fuploads%2F3fSPyUvcsQWP9rvKfrAA%2Fimage.png?alt=media&#x26;token=7be00052-ff42-47ba-a5f6-044057938db5" alt="" width="375"><figcaption><p>Component provenance</p></figcaption></figure>

### Component License(s)

All license data is available on the component card. If a single license is discovered, then the single license is shown directly on the component card, as shown below.&#x20;

<figure><img src="https://3093892275-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MbsieSiu0D66DBFP4uh%2Fuploads%2FiHPGCy280cucAMyMQyCo%2Fimage.png?alt=media&#x26;token=805f8232-cbc9-4254-904f-2ad50651eb53" alt=""><figcaption></figcaption></figure>

If multiple licenses are discovered, then you'll see "multiple" instead of the license name and will need to click on the word "multiple" to see the list of licenses, as shown below:

<figure><img src="https://3093892275-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MbsieSiu0D66DBFP4uh%2Fuploads%2F36E19wln5YwfIfoo2yxC%2Fimage.png?alt=media&#x26;token=40400c3a-1f2e-4edb-8bcd-e56eba0a06f0" alt=""><figcaption></figcaption></figure>

For both single and multiple licenses, a colored risk marker indicates the greatest license risk level. For example, if a component is licenses under MIT or Mozilla Public License 2.0, the risk marker color will be orange, to indicate the highest risk license. An example is shown below:

<figure><img src="https://3093892275-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MbsieSiu0D66DBFP4uh%2Fuploads%2FAGxOvwHksJZ3nbipRF6j%2Fimage.png?alt=media&#x26;token=3bcc6aa8-6f52-4e15-ab77-3d53acd1fcf3" alt=""><figcaption></figcaption></figure>

#### License Popup Menu

The license popup menu is available by hover over the license name. The license menu provides four options:

**View**

The view menu option opens a dialog window that displays all available data for the license in question.  An partial example is shown below.

{% hint style="info" %}
All license attributes including permissions, limitations and conditions are available in Threatrix policy engine and may be used to create polices to drive actions.
{% endhint %}

<figure><img src="https://3093892275-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MbsieSiu0D66DBFP4uh%2Fuploads%2FSLICsJDHNMuK0gm15CoZ%2Fimage.png?alt=media&#x26;token=e929097b-63a9-4ba8-b6aa-8d452898fcf7" alt=""><figcaption></figcaption></figure>

**Provenance**

In an effort to provide full transparency into the origins or artifact data, including licenses, we make every effort to verify the origins of our data and provide the provenance to the user. The provenance link will display the origin of the license, whether that's the asset text, license file or repository meta data, so that you can quickly make an informed decision about the license validity and efficacy.&#x20;

**Reject**

Rejecting a license eliminates the license from both license metrics and reports. Rejecting an existing license is not required before adding another license.&#x20;

####

#### Adding a licenses

### Component Vulnerabilities

Known vulnerabilities for components are displayed on the card and color coded by severity. The number of vulnerabilities for each severity is also provided. Shown below is an especially vulnerable version of tensorflow-cpu.

<figure><img src="https://3093892275-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MbsieSiu0D66DBFP4uh%2Fuploads%2Fq6UHYUUrdIe4oYVH0UcT%2Fimage.png?alt=media&#x26;token=21f67b3b-25a1-4188-b545-0a8317b7f379" alt=""><figcaption></figcaption></figure>

Clicking on individual metrics will produce a dialog with a complete list of all vulnerabilites in the metrics risk category.

<figure><img src="https://3093892275-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MbsieSiu0D66DBFP4uh%2Fuploads%2FTey8lEmiy2Ju9pGNDl8e%2Fimage.png?alt=media&#x26;token=d72ddc76-0d66-412f-807b-379d5c1614e9" alt="" width="563"><figcaption><p>Component vulnerabilities list</p></figcaption></figure>

From the above list, clicking on an individual vulnerability will provide the full details.

<figure><img src="https://3093892275-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MbsieSiu0D66DBFP4uh%2Fuploads%2FdVp2LXnzTAKcNzfbwMeU%2Fimage.png?alt=media&#x26;token=58b93122-b8a6-44df-a2ec-f2f64a2bc8d1" alt="" width="563"><figcaption><p>Vulnerability details screen</p></figcaption></figure>
