CAST HIGHLIGHT - SCA - What is Incomplete Detection Tab in BOM Report ?

 The "Incomplete Detection" tab in the BOM is the same as that in the dashboard under Software Composition tiled as "Additional Components with partial information's"

This tab indicates that -
The component exists in SCA database, but HL was not able to map the string/version with this particular SCA component. Thus, we only show this dependency in the second section of the SCA dashboard (Additional Components with Partial Information). In other words, components have been discovered from source but were not matched with Highlight's known components with either missing or impossible to detect version. 

This is placed in this list to let the user know there are components referenced in their dependencies and HL checks the CVEs but it is not the same level of information that is shown (no obsolescence, no accurate license information, etc.)

Here is an example - 

NB:

  • These components with missing information are not mapped with any SCA component, hence they can't be managed as such in the allow/deny component feature.
  • They appear in the SCA dashboard (dedicated data table) but also in the BOM and in the API (WS2/domains/{domainId}/applications/{applicationId}/thirdparty
  • Those components that are in a forge that Highlight do not crawl (such as https://maven.google.com/web/index.html Google's Maven Repository) may also be listed in the table Additional Components with partial information’s.

Zendesk Ticket Number  

#28066, 50523, 52594

 

Related Article

CAST HIGHLIGHT - SCA - OSS components in Additional Component with Partial Information

Proprietary Component Governance

 

Additional Resources

CAST Highlight Troubleshooting Guides

CAST Highlight Product Documentation

 

Have more questions? Submit a request

Comments

Powered by Zendesk