DependencyTrack / DependencyTrack/dependency-track

Feature: Import vulnerabilities from BOM

Open
#1,297 6 comments 1 reaction 0 assignees View on GitHub
enhancement
Dominant language
Java
Stars
4.2k
Forks
811
Avg merge
8h 39m
Merged PRs (30d)
237

Description

Some tools out there (Grype) are able to generate vulnerabilities using the CycloneDX vulnerabilities extension: `http://cyclonedx.org/schema/ext/vulnerability/1.0` and often make use of different vulnerability sources such as GHSA. It'd be great if submitting a BOM with vulnerabilities also populated the internal db with any unknown vulnerabilities from these BOM files.

### Current Behavior:
BOM file is imported and vulnerabilities ignored

### Proposed Behavior:
BOM file imported, vulnerabilities and components parsed and database populated with unknown vulnerabilities.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.