- Analytics reports: The analytics report provides a high-level view of vulnerability trends over time for the selected scope. It includes insights into newly discovered and resolved vulnerabilities, broken down by severity and tracked across defined time periods. The report also highlights remediation patterns, such as how long issues typically take to resolve, helping teams assess risk posture and remediation efficiency. Overall, it supports trend analysis, prioritization, and offline review of security metrics.
- Findings reports: The findings report provides a detailed view of individual security findings identified within the selected scope. It includes information such as vulnerability details, severity, affected components, and contextual metadata to help teams understand risk and impact. The report also captures remediation-related context, such as fix availability, reachability, and policy signals, to support prioritization. Overall, it supports deep analysis, audits, and sharing actionable security findings for offline review.
- License Notice reports: The license notice report lists the open source dependencies in the selected scope along with their license texts, copyright notices, and source code locations. Include a license notice report when you distribute software that contains open source dependencies.
Create an analytics or findings report
Create an analytics report or findings report to export vulnerability trend or findings data for offline analysis.- Select Reports from the left sidebar.
- Click the dropdown arrow next to Create Report and select a report type.
- Analytics Report: To export aggregated analytics data based on the selected filters.
- Findings Report: To export detailed findings data based on the selected filters.
- Choose the output format for the report. Analytics reports are available in JSON format. Findings reports are available in PDF.
- Define which projects the report includes. If you don’t select any projects, the report includes all projects by default.
- Selected projects: Includes only explicitly selected projects.
- Selected project tags: Includes projects matching specific tags.
- Choose the following filters to refine the data included in the report.
- Severity: Filter the data based on finding severity such as Critical, High, Medium, or Low (labeled C, H, M, and L in the user interface).
- Category: Filter the findings by category such as AI models, vulnerability, SCA, SAST, secrets, and container.
- Attributes: Narrow down the list based on the following range of factors:
- if a patch is available to fix the findings
- if the vulnerable function is reachable
- if the dependency is reachable
- if the dependency originates from a current repository or a current tenant
- if the dependency is a test dependency
- if the dependency’s discovery type is manifest, phantom, or segment match
- if the finding originates from itself, direct, or a transitive dependency
- filter the findings by the Exploited tag from CISA KEV
- filter the findings by the Warn or Break the Build options set in the action policy.
- Time Period: Restrict the report to findings or events within a selected range. Choose a preset such as Last Day, Last Week, Last Month, Last 60 Days, Last 90 Days, or All Time, or set a custom date range.
- Click Create Report to generate your report.
Create a license notice report Beta
Create a notice report to export license texts, copyright notices, and attribution information for one or more projects or packages.- Select Reports from the left sidebar.
- From the Create Report dropdown, select License Notice Report.
- Choose the output format for the report. Available formats are TXT and Markdown.
- Optionally, enter a Report Name. Endor Labs assigns a default name if you leave this blank
-
Under Scope, choose Select Projects or Select Packages, then select at least one project or package. You can select up to 100 projects or up to 500 packages.
You must select at least one project or package. If you select more than 100 projects or more than 500 packages, Endor Labs shows a validation error until you correct the selection.
-
Choose the following filters to refine the data included in the report.
- Multi-Licenses: Filter based on which license to use when a dependency has multiple licenses.
- Select All to include every license associated with the dependency.
- Select Most Permissive to include only the most permissive license.
- Type: Filter based on whether the license was declared by the dependency or discovered during scanning.
- Select All to include both declared and discovered licenses.
- Select Declared Only to include only licenses declared by the dependency.
- Select Discovered Only to include only licenses discovered during scanning.
- License Category: Select one or more license categories, such as Permissive, Copyleft, or Public Domain, to include in the report. By default, all license categories are included.
- Multi-Licenses: Filter based on which license to use when a dependency has multiple licenses.
- Toggle Include Copyright information to include copyright statements in the report. When you include copyright information, the Components section of the report lists the copyright statements found for each dependency, and includes dependencies that have copyright statements but no license information. Otherwise, Endor Labs omits those dependencies so the report contains no empty entries.
- Select Use custom disclaimer to the notice file to enter disclaimer text to show at the top of the notice file. You can enter up to 8,192 characters of disclaimer text.
- Click Create Report to generate your report.
Manage reports
You can track your report status and access report outputs after generating them.-
Select Reports from the left sidebar to view the details of all the reports generated for your namespace.
- Status indicator: Shows the report generation status. The following statuses are possible:
- Report name: The report type and creation timestamp.
- Report type: The type of the report created such as analytics report, findings report, or license notice report
- Created by: The user who generated the report.
- Created date: Date and time of report creation.
- Select a report to view additional details including the report scope and applied filters. For a license notice report, the details also show the file format, license type, multi-license policy, copyrights setting, and custom disclaimer.
- To download a report, click the three vertical dots and click Download.
- To delete a report, click the three vertical dots and click Delete.