src/site/markdown/analyzers/oss-index-analyzer.md
Uses the Sonatype Guide OSS Index APIs to report on vulnerabilities not found in the NVD. The collection of identified PURL/Package URL identifiers are submitted to the OSS Index for analysis and the resulting identified vulnerabilities are included in the report. In addition, vulnerabilities found in both the NVD and OSS Index may have additional references added.
This analyzer requires an internet connection, and authentication is mandatory. If no credentials are provided, this analyzer will be disabled. Review the configuration for the specific dependency-check integration used for more information on how to configure the URL and credentials for this analyzer.
During 2026, the Sonatype OSS Index API is being migrated to become part of the Sonatype Guide platform.
During this migration users will need to make some minor changes.
12.2.1+ (if using defaults)password for authentication (username is optional)For more details on this migration see: