About custom components
You may want to use a component in your BOM that is not available from Black Duck KnowledgeBase; for example, your project uses an open source component that is not tracked by the Black Duck KB or there is a commercial component you want to add to your BOM. So that your BOM accurately reflects your project, users with the Component Manager role can create and manage custom components which can then be added to a BOM.
Black Duck provides the information Component Managers need to successfully manage their custom components. They can use the:
-
Custom Component Name Overview tab to view the versions for a component, including the status, description, and tags for this custom component.
You can also use this tab to create tags for the custom component.
-
Custom Component Name Settings tab to view and/or edit the details of a component.
Use this tab to delete a custom component.
-
Custom Component Name > Version Details tab which provides details of this component version and lists the projects used by a custom component version.
Component Managers must have permission to view the projects for them to appear on this page.
-
Custom Component Name > Version Settings tab to view and/or edit the details of a component version.
Use this tab to delete a custom component version.
Note the following:
- In the BOM:
The match type for a custom component added to a BOM is Manually Added.
Custom components display license risk. (Note that the license risk shown is determined by the license selected for this component.) No security risk values are shown as no security vulnerabilities are associated with the custom component. Also, no operational risk is shown.
-
Policy Managers can create policy rules for custom components.
-
You can use the search feature for custom components. A component filter, Component Source, has the value Black Duck Custom Component for custom components.
-
In the
components_date_time.csv
andbom_component_custom_fields_date_time.csv
files in the Project Version report, a new column, labeled Source/Type denotes whether the component is a custom component (value of CUSTOM_COMPONENT) or a component that is managed by Black Duck KnowledgeBase (value of KB_COMPONENT). -
Custom components do not have origins.