- Argentina
- Australia
- Bangladesh
- Belarus
- Belgium
- Brazil
- Bulgaria
- Canada
- China
- Costa Rica
- Egypt
- France
- Germany
- Hong Kong
- India
- Indonesia
- Ireland
- Israel
- Italy
- Japan
- Kenya
- Kuwait
- Malaysia
- Mexico
- Netherlands
- New Zealand
- Nigeria
- Pakistan
- Philippines
- Poland
- Qatar
- Romania
- Russia
- Saudi Arabia
- Singapore
- South Africa
- Spain
- Sri Lanka
- Sweden
- Switzerland
- Thailand
- Turkey
- UAE
- Ukraine
- United Kingdom
- United States
WhiteSource FAQs
/*= Html::a(
$default_button_text,
'javascript:void(0);',
$default_req_button
) */?>
Unverified Vendor
COMMUNITY FEEDBACK SCORE
- 4.00
- 2 Reviews
RANKINGS & RATINGS
RANK
-
6 / 87
-
16 / 60
-
84 / 431
Work for WhiteSource? Manage Profile
Ask WhiteSource a Question
0
votes
Updated September 1, 2016 We are using something else right now, but are disappointed. Does WhiteSource offer any migration assistance?
- Answer
-
151 Views
0
votes
Updated January 14, 2020 Do you offer an on-premise solution?
- Answer
- Read 1 Answers
-
99 Views
WhiteSource | January 14, 2020
WhiteSource is a cloud-based service, but we also offer an on-premise option, if necessary. It’s important to emphasize that we do not scan your code. We also offer a dedicated instances option. (more)
0
votes
Updated April 22, 2016 Is WhiteSource offered in different languages? If so, which ones?
- Answer
-
121 Views
0
votes
Updated October 13, 2017 Do we get future versions of the software, or do upgrades cost extra?
- Answer
-
124 Views
0
votes
Updated January 14, 2020 Is WhiteSource for Containers a separate product?
- Answer
- Read 1 Answers
-
111 Views
WhiteSource | January 14, 2020
No. WhiteSource for Containers is part of the WhiteSource product. It integrates with more than 15 different tools: CI/CD, build tools, image registries, and containers management platforms, to give you an updated view of your container’s lifecycle. You can also define automated policies to block unwanted open source components from entering your containers. (more)
0
votes
Updated January 14, 2020 How does your product work?
- Answer
- Read 1 Answers
-
102 Views
WhiteSource | January 14, 2020
Our plugins integrate with your repositories, build tools, CI servers and more. It calculates the digital signature for all your components without ever scanning your code. It then cross-reference the digital signatures with the ones in WhiteSource database to detect the open source components in your products. An immediate up-to-date report is generated with all components and issues detected. It does that every time you run your build. (more)
0
votes
Updated January 14, 2020 What is WhiteSource?
- Answer
- Read 1 Answers
-
126 Views
WhiteSource | January 14, 2020
WhiteSource automates the entire process of open source component selection, approval and management, including detection and remediation of security and compliance issues. It integrates with all stages of your software development lifecycle (SDLC) to alert in real time and help you fix issues faster and easier. (more)
0
votes
Updated January 14, 2020 Where does the vulnerability information come from?
- Answer
- Read 1 Answers
-
105 Views
WhiteSource | January 14, 2020
The WhiteSource database is the biggest and most mature database of open source vulnerabilities. It contains more than 300,000 vulnerable components which are aggregated from the CVE/NVD, and various other sources like the GitHub issue tracker, security advisories, and open source projects issue trackers.
WhiteSource uses a proprietary patented algorithm that matches between vulnerability and only the impacted version, thus guaranteeing no false positives that waste developers’ time. (more)
WhiteSource uses a proprietary patented algorithm that matches between vulnerability and only the impacted version, thus guaranteeing no false positives that waste developers’ time. (more)
0
votes
Updated January 14, 2020 What type of reports you offer?
- Answer
- Read 1 Answers
-
89 Views
WhiteSource | January 14, 2020
We offer a variety of reports that will help you monitor all of your open source activity such as an Inventory report, due diligence report, high severity bugs report and vulnerability report and many more. You can see some examples at the bottom of this page. (more)
0
votes
Updated January 14, 2020 Can you enforce customized policies? How?
- Answer
- Read 1 Answers
-
91 Views
WhiteSource | January 14, 2020
Yes, WhiteSource enforces policies automatically throughout the software development process. You can define your policies according to security vulnerabilities severity, open source license type, software bugs severity, age of a component and many more. You can approve, reject, initiate an approval flow or open an issue ticket based on your criteria and definitions.
In addition, WhiteSource also offers a browser extension, which notifies your developers if a certain component meets your organization’s policies while searching online in the worldwide web without downloading the component. (more)
In addition, WhiteSource also offers a browser extension, which notifies your developers if a certain component meets your organization’s policies while searching online in the worldwide web without downloading the component. (more)