Identifying Open Source libraries produces an application bill of materials detailing a list of identified components and risks. The result is a report of identified Open Source components and known vulnerabilities leveraging Sonatype. No code leaves the FoD environment and the data found does not impact your vulnerability count or risk rating.