DevOps.com

  • Latest
    • Articles
    • Features
    • Most Read
    • News
    • News Releases
  • Topics
    • AI
    • Continuous Delivery
    • Continuous Testing
    • Cloud
    • Culture
    • DevSecOps
    • Enterprise DevOps
    • Leadership Suite
    • DevOps Practice
    • ROELBOB
    • DevOps Toolbox
    • IT as Code
  • Videos/Podcasts
    • DevOps Chats
    • DevOps Unbound
  • Webinars
    • Upcoming
    • On-Demand Webinars
  • Library
  • Events
    • Upcoming Events
    • On-Demand Events
  • Sponsored Communities
    • AWS Community Hub
    • CloudBees
    • IT as Code
    • Rocket on DevOps.com
    • Traceable on DevOps.com
    • Quali on DevOps.com
  • Related Sites
    • Techstrong Group
    • Container Journal
    • Security Boulevard
    • Techstrong Research
    • DevOps Chat
    • DevOps Dozen
    • DevOps TV
    • Digital Anarchist
  • Media Kit
  • About
  • AI
  • Cloud
  • Continuous Delivery
  • Continuous Testing
  • DevSecOps
  • DevOps Onramp
  • Practices
  • ROELBOB
  • Low-Code/No-Code
  • IT as Code
  • More
    • Application Performance Management/Monitoring
    • Culture
    • Enterprise DevOps

Home » Blogs » DevOps and Open Technologies » Open Source software license and security management with WhiteSource

Open Source software license and security management with WhiteSource

By: vishal sahasrabuddhe on September 18, 2015 1 Comment

With the growing speed and availability of open source components, it becomes easy to add features and integration of software with other components which makes software development easier. But there are a few points to be remembered while using any open source component.

Recent Posts By vishal sahasrabuddhe
  • Checks and Balances to Build Stronger Code
  • Make Presentation and Training More Effective
  • Release Engineering vs. Release Management
More from vishal sahasrabuddhe
Related Posts
  • Open Source software license and security management with WhiteSource
  • WhiteSource Rebrands as Mend, Introduces Industry-First Automated Remediation with the Mend Application Security Platform
  • SBOMs 101: What You Need to Know
    Related Categories
  • Blogs
  • DevOps and Open Technologies
  • DevOps Toolbox
    Related Topics
  • open source
  • open source governance
  • open source software
Show more
Show less
  • Security vulnerabilities
  • Licensing risks of open source component.
  • Outdated open source components.

The above are a very important part of the the software development life cycle to eliminate any discrepancies related to security or legal issues.

CloudNativeDay 2022

WhiteSource provides one fine platform to solve such issues without putting in much effort by developers, They can concentrate on core development instead of spending time on finding these issues which can be easily handled by WhiteSource.

WhiteSource is an open source management solution which does

  • Open source licensing and compliance management
  • Open Source security vulnerabilities alerts and management
  • Executive dashboards, policy enforcement, and reporting

WhiteSource checks your software and generates open source inventory report, including detail from open source. The WhiteSource gathers information on open source components and they keep the inventory updated.

WhiteSource covers almost all commonly used languages and provide detail report, This tool can track all your open source components used knowing or unknowingly within your software.

It sends alerts for any potential issue observed in open source component used by software. It does check for outdated/expired component, It provides detail on security issues found in any opensource component.

WhiteSource does not store (keep track of) any software component which is not open source, this means it’s safe and your code will not be touched.

CI tool Integration (Jenkins)

The best part of the tool is that it has plugin available for the widely used CI tool – Jenkins.

WhiteSource Jenkins plugin is the best and easy way to integrate with WhiteSource to run the checks during build and integration phase in an automatic way.

Its very easy to use, not even just for Maven project also for free style projects.

Easy to configure and use within project. Only token needs to be added and plugin automatically takes care of everything.

Multiple options are available at job level to define the project and modules to be included.

Logs are pretty descriptive when plugin start processing in Jenkins job.

WhiteSource basic principle talks about

Managing the component vs governing the component.

Developers can leave the managing part up to WhiteSource and only concentrate on the issue of governance at the component level in software.

Filed Under: Blogs, DevOps and Open Technologies, DevOps Toolbox Tagged With: open source, open source governance, open source software

Sponsored Content
Featured eBook
The 101 of Continuous Software Delivery

The 101 of Continuous Software Delivery

Now, more than ever, companies who rapidly react to changing market conditions and customer behavior will have a competitive edge.  Innovation-driven response is successful not only when a company has new ideas, but also when the software needed to implement them is delivered quickly. Companies who have weathered recent events ... Read More
« Announcing Orca v2.0: Application Configuration Automation for Linux and Windows
The Scalable Path to DevOps Career Training & Development »

TechStrong TV – Live

Click full-screen to enable volume control
Watch latest episodes and shows

Upcoming Webinars

DevOps Institute's 2022 Global SRE Pulse Survey
Tuesday, August 9, 2022 - 11:00 am EDT
VSM, an Ideal Framework for Continuous Security Dashboards
Wednesday, August 10, 2022 - 11:00 am EDT
LIVE WORKSHOP - Accelerate Software Delivery With Value Stream Mapping
Wednesday, August 10, 2022 - 1:00 pm EDT

Latest from DevOps.com

Don’t Let Developer Toil Affect the Business Value of Your Apps
August 8, 2022 | Michael Cote
Leverage Empirical Data to Avoid DevOps Burnout
August 8, 2022 | Bill Doerrfeld
Learn Something New Every (Cloud-Native) Day
August 8, 2022 | Mike Rothman
Putting the Security Into DevSecOps
August 5, 2022 | Ross Moore
Recession! DevOps Hiring Freeze | Data Centers Suck (Power) | Intel to ‘be’ Wi-Fi 7
August 4, 2022 | Richi Jennings

Get The Top Stories of the Week

  • View DevOps.com Privacy Policy
  • This field is for validation purposes and should be left unchanged.

Download Free eBook

The State of the CI/CD/ARA Market: Convergence
https://library.devops.com/the-state-of-the-ci/cd/ara-market

Most Read on DevOps.com

Recession! DevOps Hiring Freeze | Data Centers Suck (Power) ...
August 4, 2022 | Richi Jennings
Three Key Steps To Going Multi-Cloud
August 2, 2022 | Aran Khanna
Developer-led Landscape & 2022 Outlook
August 3, 2022 | Alan Shimel
Palo Alto Networks Extends Checkov Tool for Securing Infrast...
August 3, 2022 | Mike Vizard
Orgs Struggle to Get App Modernization Right
August 4, 2022 | Mike Vizard

On-Demand Webinars

DevOps.com Webinar ReplaysDevOps.com Webinar Replays
  • Home
  • About DevOps.com
  • Meet our Authors
  • Write for DevOps.com
  • Media Kit
  • Sponsor Info
  • Copyright
  • TOS
  • Privacy Policy

Powered by Techstrong Group, Inc.

© 2022 ·Techstrong Group, Inc.All rights reserved.