DependencyTrack / DependencyTrack/dependency-track
Adding new hardware component without having a CPE assigned
- Dominant language
- Java
- Stars
- 4.2k
- Forks
- 811
- Avg merge
- 8h 39m
- Merged PRs (30d)
- 237
Description
The enhancement may already be reported! Please search for the enhancement before creating one.
### Current Behavior:
We need to enter the complete CPE id (cpe:2.3:h-------) to get the CVEs reported against a particular hardware component.
This is the case with components with affected configuration has only hardware in it (only cpe:2.3:h).
e.g. https://nvd.nist.gov/vuln/detail/CVE-2017-5754, CPE id: cpe:2.3:h:intel:atom_c:c2308:*:*:*:*:*:*:*
### Proposed Behavior:
Currently DT is unable to track future CVEs on hardware components which may reported if there is no CPE id assigned already. This is the case with hardware components which doesn't have any CVEs reported yet.
e.g. Adding a hardware component say 'stm32l5' or 'stm32U5' which doesn't have any CVEs reported yet. How to add this component into DT if we don't know the CPE.
Contributor guide
Research direction
The issue names no files, tests, or entry points. Start by tracing how hardware components, complete CPE identifiers, and NVD CVEs are handled, then compare components with existing CPEs against examples such as stm32l5 or stm32U5. Done means future CVEs can be tracked for a hardware component without an assigned CPE.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100