CycloneDX / CycloneDX/cyclonedx-linux-generator
Using generated SBOMs in DependencyTrack
Open
- Dominant language
- Java
- Stars
- 56
- Forks
- 13
- PR merge metrics
- No merged PRs in 30d
Description
Hi!
After testing the tool on a ubuntu VM, I end up with a large SBOM (~2k entries).
When importing this SBOM into DependencyTrack, components are created - but only filled with "name" and "version" (so no group or cpe). Should this already be enough for DependencyTrack to identify vulnerable components (apparently no vulnerabilities are present in my test sample)?
I think to recall that the fuzzy matching was removed as it created too many false positives?
Is further work planned in this direction?
Contributor guide
Assessment
This issue has not been assessed yet.