CycloneDX / CycloneDX/cyclonedx-linux-generator

Using generated SBOMs in DependencyTrack

Open
#11 2 comments 1 reaction 0 assignees View on GitHub
Dominant language
Java
Stars
56
Forks
13
PR merge metrics
No merged PRs in 30d

Description

Hi!

After testing the tool on a ubuntu VM, I end up with a large SBOM (~2k entries).
When importing this SBOM into DependencyTrack, components are created - but only filled with "name" and "version" (so no group or cpe). Should this already be enough for DependencyTrack to identify vulnerable components (apparently no vulnerabilities are present in my test sample)?
I think to recall that the fuzzy matching was removed as it created too many false positives?

Is further work planned in this direction?

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.