If enabled, the Nexus analyzer will run as part of a Dependency-Check scan. The Nexus analyzer will search the repository for the SHA-1 hash of the dependency. If found, the groupId, artifactId, and version are added as Vendor, Product, and Version evidence, respectively. Furthermore, it adds a new Identifier with the Maven coordinates for the jar identified.

When used with internal Nexus repositories, non-Maven jars (such as vendor-provided libraries, etc.) can be identified with greater accuracy.