Log in

WhiteSource provides several methods for user login. In GÉANT, use the single sign-on login (SSO):

  1. Open WhiteSource login at https://app-eu.whitesourcesoftware.com/
  2. Click Sign in with SSO.

  3. Enter your GÉANT email address to be forwarded to the GÉANT login page.

  4. Log in with your identity provider as you would for other GÉANT services.
  5. Your GÉANT WhiteSource Home Page opens.

On subsequent logins, you can go directly to https://app-eu.whitesourcesoftware.com/Wss/WSS.html - depending on saved cookies, some or all of the previous steps may be skipped.

For more information on accounts management and customisation of WhiteSource and products visibility, see Re: MANUAL: Accessing WhiteSource and visibility levels (THIS PAGE SHOULD BE MOVED!).

Dashboard (key information in WhiteSource user interface)

Many things are shown on the WhiteSource dashboard. To understand them, read the following text which is focused on licences and interpretation of the provided data for GÉANT.

The dashboard in WhiteSource can be at the organisation (GÉANT), Product or Project level. A detailed explanation of the terms Products, Projects, and Organizations in WS can be found here. In a nutshell: your team is working on a WhiteSource 'product' which may consist of several related pieces of software, which are in WhiteSource called 'projects'.

The dashboard at the organisation level is WhiteSource Home Page; at the product level, it is Product Page, and at the project level, Project Page. Regardless of the level, the dashboard contains the following key information:

Detailed information about the libraries

The Library table in the header has a link to the Inventory Report. This report is a tabular view of detailed information about open source libraries. The Inventory Report provides the following columns of information per library:

Detailed information about the licences (Licence Analysis)

This section provides an overview of the license distribution of the organization (or product, project), showing which licences are used and how many libraries are associated with each license.  The distribution of licences is shown in the pie chart. The following information is displayed for each licence:

The Project dashboard within this section has a link View In Due Diligence Report. This report is a tabular view of detailed information about all detected licences. The Due Diligence Report provides the following columns of information:

Finding your product and projects

The Product page displays detailed information about a specific product (the result of a product scan for a specific version). The product page for a product is accessed from the Products menu item of the main menu.

The Project page displays detailed information about a specific project within a previously selected product. It can be accessed from the Projects menu item in the main menu.




The difference in interpreting the presence of a problematic library when assessing the situation vs exploring license compatibility and compliance options vs checking compliance with the established product's licence

same policy/licence across projects in the product vs differentiated project policies


Interpreting Risk Report

The Risk Report is a tool that provides a view of all aspects of open-source libraries concerning their licenses, security, quality and compliance.

Creating the Report

  1. The report is available from the "Reports" menu. 
  2. Define the scope for which the report should be created. The defaults scope is Organizational (GÉANT), or you can select any individual product and/or project
  3. Click Apply

Understanding the Report Data

The report contains a number of panels and tables displaying risk-related information. The Risk Report has the following sections:

  1. How do we compare? - This section compares the results of measuring the level of risk and compliance of the selected range (GÉANT, product or project) with the overall average statistics calculated for WS clients. Includes the following three charts: Vulnerable Libraries, Policy Violating Libraries, Outdated Libraries.
  2. Security - This panel displays the vulnerability score (base on the highest severity vulnerability), the number of vulnerable components out of total components, severity distribution, aging security vulnerabilities, license risk distribution, outdated components out of total components and libraries with multiple versions.
  3. License Risks and Compliance - This panel provides an overview of the License Distribution of the organization (or product), showing which licenses are used and how many libraries are associated with each license.
  4. Quality - This panel provides information about any outdated libraries
  5. Additional Risk Information - Contains detailed tables with various component-level breakdowns.

Exporting the Report

Click Export to PDF at the top right of the report and export the Risk report as a PDF file.

Interpreting License Compatibility Report

The License Compatibility Report provides information on the compatibility of libraries with different software licenses distributed together in the same product or project. 

Creating the Report

  1. The report is available from the "Reports" menu. 
  2. Select the scope for which the report should be created - open the dropdown menu next to the report name and select the product or specific project on which you want to base the report

  3. Click Apply and wait for the data to load into the report preview table.

Understanding the Report Data

The License Compatibility Report provides the following columns of information in a table:

Customising visibility

The GÉANT WhiteSource admins can always see all scanned GÉANT products.

By default, anyone who applies to WhiteSource can see the content of all non-restricted GÉANT products and projects in WhiteSource. It is possible to restrict read permissions to scan results for specific products and projects. You can contact the GEANT WhiteSource support to get access to a specific project that has limited visibility or to restrict the permissions for a specified product or project.