Getting Started with Sonatype Guide
Getting started with Sonatype Guide is simple. You can begin exploring Guide with or without signing in, depending on how deeply you want to research open-source components and vulnerabilities.
If you’re just getting started, you can use Guide anonymously to search for components and publicly disclosed vulnerabilities. This allows you toi quickly explore open-source intelligence and decide when you’re ready to sign up.
When you’re ready to unlock deeper insights and additional capabilities, you can sign up for a free account. Once you’ve registered with Sonatype, you will be invited to sign up for Guide with either your Google or GitHub account.
The sections below walk you through signing up for Guide as well as understanding some of the other elements you will see in your Organization page.
Using Sonatype Guide Without Signing In
You can start using Sonatype Guide immediately without creating an account.
As an anonymous user, you can:
Search for open-source components.
Search for publicly disclosed vulnerabilities (such as CVEs)
Browse component and vulnerability results
Review basic details such as ecosystem, latest version, licenses, and severity
Anonymous access is ideal for quick research and initial exploration. When you reach features or insights that required an account, Guide will prompt you to sign up.
See Anonymous Access to Sonatype Guide for details on available features and usage limits.
Signing Up for Guide
Signing up for Guide takes only seconds.
Guide allows you to sign up with either your existing GitHub or Google account. Select your desired option in the sign-in window.
Once you've signed up, you'll be redirected to the Guide home screen.
From here, you can jump right in to researching, automating, and integrating with Sonatype Guide.
Understanding Policy
Managing acceptable risk through policies allows Guide to provide scannable “Meets Policy” checkpoints in a number of different areas across the application.
You can see the policies your Guide instance is using by selecting the Policy option under Settings from the main navigation menu.
Note
Note that the policies Guide uses are not editable at this time.
![]() |
Sonatype Guide comes with three built-in policies:
No Malware – This policy prevents any dependency containing malware (i.e., malicious open-source components) from passing a policy check.
No CVSS 7.0+ – Any component version with a CVSS score of 7.0 or higher (High or Critical) will fail policy checks.
No Copyleft Licenses – Packages under copyleft license families will fail policy checks. These licenses impose redistribution obligations that can cause conflict with commercial use.
Components that fail policy still remain searchable for transparency. However, to allow you to quickly exclude certain components at a glance, policy compliance is displayed in a few locations throughout Guide:
The Policy Compliance section of a component page
The Meets Policy column in version tables
The Meets Policy field in search results
