Which license risk profile to use?
In CAST Highlight, Open Source components used by your applications are automatically detected with their licenses. Depending on the constraints, permissions, and other attributes of these licenses (i.e. license rulebook), CAST Highlight automatically determines a level of risk (high, medium, low) of using such a component within an application. While you can use the out-of-the-box license risk profile provided by CAST, you may also want to tweak it with some adjustments, or just start with a new License Risk profile from scratch by applying your own license policy. License risk profile management in CAST Highlight is very flexible and can be used by root-level Portfolio Managers in several ways:- The default license risk profile is designed to identify common license risks for a typical application developed by commercial organizations. This article explains how this license risk profile is built. If you’re unsure about a specific license or risk categorization, we recommend you consult with an open source legal expert.
- You can create your own license risk profile from CAST Highlight’s user interface (Manage License Profiles) by manually determining the level of risk (high, medium, low) for each license.
- You can use the license rulebook to automatically determine the level of risk for each license based on each licenses’ properties and terms (e.g. must disclose source code, permissive vs. strong copyleft, etc.). See how this is done in the next section of this article.
How to create a license risk profile based on the license rulebook
Now, let’s see how to quickly create a license risk profile based on the license rulebook.Go to MANAGE > Manage License Profiles and click on the “Add License Risk Profile” button. Note that if you want to start with an existing license risk profile as a basis, you can also duplicate them.From here, give your new license risk profile a name and a description. As indicated earlier in this post, you can manually define the level of risk for each license from the first “License Risk Configuration” tab. But let’s see how to automatically generate it with the license rulebook, by clicking on the second “License Rulebook Configuration” tab.From this screen, you can make each element of the rulebook positively or negatively contribute to the license risk score:- A positive score indicates that the license property decreases the license risk (e.g., CAN distribute the software to third parties)
- A negative score indicates it increases the license risk (e.g., Strong copyleft)
How to roll out license risk profiles across your portfolio
From here, you can edit, delete, or even duplicate an existing license risk profile by clicking on the different icons, but you can also define how these profiles will be applied across your application portfolio.- Apply a default license risk profile: to make a specific license risk profile the one that will be applied by default to all applications, check the radio button on the right. All licenses found in existing applications will be categorized according to this profile, future onboarded applications will also be scored according to this license risk profile.
- Apply a specific license risk profile to specific applications: depending on the context of an application (might be SaaS or internal application, or perhaps an Open Source project), you may want to apply a specific license risk profile to it. For this, click on the “chain” icon, then select the applications from the right table to apply this profile to them and finally click on “Save Application Selection”.
For reference only. For the complete details please refer the original article
https://doc.casthighlight.com/feature-focus-automatically-generate-license-risk-profile-based-cast-highlight-license-rulebook/
https://doc.casthighlight.com/feature-focus-automatically-generate-license-risk-profile-based-cast-highlight-license-rulebook/
Comments