<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Guillermo Varela</title>
    <description>The latest articles on DEV Community by Guillermo Varela (@guillermovarela).</description>
    <link>https://dev.to/guillermovarela</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F578870%2Fb034a6ff-f4fe-47b3-87de-9fafd33e874f.jpeg</url>
      <title>DEV Community: Guillermo Varela</title>
      <link>https://dev.to/guillermovarela</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/guillermovarela"/>
    <language>en</language>
    <item>
      <title>Happy 1st Birthday to Sonatype Gradle Scan Plugin - Enter Sherlock Trunks!</title>
      <dc:creator>Guillermo Varela</dc:creator>
      <pubDate>Fri, 19 Feb 2021 19:16:08 +0000</pubDate>
      <link>https://dev.to/guillermovarela/happy-1st-birthday-to-sonatype-gradle-scan-plugin-enter-sherlock-trunks-on3</link>
      <guid>https://dev.to/guillermovarela/happy-1st-birthday-to-sonatype-gradle-scan-plugin-enter-sherlock-trunks-on3</guid>
      <description>&lt;p&gt;It's been over a year since the release of the open source Gradle plugin to scan, evaluate, and audit Gradle project dependencies aiming to keep developers safe from any vulnerabilities such libraries could bring: &lt;a href="https://github.com/sonatype-nexus-community/scan-gradle-plugin"&gt;https://github.com/sonatype-nexus-community/scan-gradle-plugin&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Following the Open Source mindset we proudly carry at Sonatype, this plugin has grown not only based on internal initiatives (many of them from my colleague &lt;a href="https://github.com/shaikhu"&gt;&lt;br&gt;
Usman Shaikh&lt;/a&gt;) but also from feedback given by users of both our free &lt;a href="https://ossindex.sonatype.org/"&gt;OSS Index&lt;/a&gt; service and the paid platform &lt;a href="https://www.sonatype.com/nexus/lifecycle"&gt;Nexus Lifecycle&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Some of the improvements have been:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Better visualization for OSS Index results&lt;/strong&gt;: from the initial plain text list of dependencies and vulnerabilities now the output supports a tabular-like and colored output to make the results easier to read and understand with an option to also get a tree structure to identify which transitive dependency is bringing vulnerabilities to a project:
&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--KIT6E0D5--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://dev-to-uploads.s3.amazonaws.com/i/8qyqgj172uqzjpeim848.png" alt="tabular list oss index output"&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--WTkdvMWP--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://dev-to-uploads.s3.amazonaws.com/i/mne0d8mkb39nlxqkh3dt.png" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--WTkdvMWP--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://dev-to-uploads.s3.amazonaws.com/i/mne0d8mkb39nlxqkh3dt.png" alt="dependencies tree oss index output"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Option to view only vulnerable dependencies in OSS Index results&lt;/strong&gt;: if you prefer focusing in addressing the vulnerabilities ;)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;New flag to include dependencies from all configurations&lt;/strong&gt;: Gradle builds are highly customizable, so now it's possible to include dependencies beyond the default configurations &lt;code&gt;compileClasspath&lt;/code&gt; and &lt;code&gt;releaseCompileClasspath&lt;/code&gt; for both OSS Index and Nexus Lifecycle.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Improved support for Android projects&lt;/strong&gt;: projects with build variants and product flavors are now fully supported.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;InnerSource Insight has arrived&lt;/strong&gt;: Nexus Lifecycle customers can now have a better understanding of vulnerabilities carried over from InnerSource components and transitive dependencies. More details about InnerSource Insight at: &lt;a href="https://help.sonatype.com/iqserver/reporting/application-composition-report/innersource-insight"&gt;https://help.sonatype.com/iqserver/reporting/application-composition-report/innersource-insight&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Continuously improved documentation&lt;/strong&gt;: We do our best to always keep the &lt;a href="https://github.com/sonatype-nexus-community/scan-gradle-plugin/blob/master/README.md"&gt;README.md&lt;/a&gt; file out to date with all new features and instructions so users can start using the plugin according to their needs and remediate vulnerabilities quickly!&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;But possible the news that brought the most joy for us was the arrival of our new mascot: &lt;strong&gt;Sherlock Trunks!!!&lt;/strong&gt;&lt;br&gt;
&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--i17JAKEy--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://dev-to-uploads.s3.amazonaws.com/i/smcgamg1e48w8luwuo9q.png" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--i17JAKEy--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://dev-to-uploads.s3.amazonaws.com/i/smcgamg1e48w8luwuo9q.png" alt="Sherlock Trunks"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Hopefully our new friend will motive us and the plugin's users to be in an inquisitive mood, looking for vulnerabilities from Open Source dependencies in all kind of Gradle projects while also finding new ways to keep improving this plugin.&lt;/p&gt;

&lt;p&gt;Thanks to all who have used the plugin and help making it better by creating issues with your feedback and requests.&lt;/p&gt;

&lt;p&gt;You haven't used it yet? Well, using OSS Index is completely free so go for it!&lt;/p&gt;

</description>
      <category>gradle</category>
      <category>vulnerabilities</category>
      <category>ossindex</category>
      <category>dependencies</category>
    </item>
  </channel>
</rss>
