DependencyTrack / DependencyTrack/dependency-track

Investigate Impact/Utility of CVE JSON 5.0 to Dependency-Track

Open
#1,563 1 comment 0 reactions 0 assignees View on GitHub
spike / research
Dominant language
Java
Stars
4.2k
Forks
811
Avg merge
9h 4m
Merged PRs (30d)
229

Description

From [Changes Coming to CVE Record Format JSON and CVE List Content Downloads](https://www.cve.org/Media/News/item/news/2022/01/11/Changes-Coming-to-CVE-Record):

> CVE JSON 5.0 is a major upgrade to JSON 4.0 that further normalizes and enriches how CVE information is presented. It adds several new data fields to CVE Records. In addition to the required data of CVE ID number, affected product(s), affected version(s), and public references, JSON 5.0 CVE Records will now include optional data such as severity scores, credit for researchers, additional languages, affected product lists, additional references, ability for community contributions, etc. This optional data will enhance CVE Records for both downstream users and the overall vulnerability management community.

Will this impact Dependency-Track or (better still) provide opportunity for improving Dependency-Track?

If the answer is "yes" then this issue can be changed from "investigate" to "implement something" (or a new issue created).

Contributor guide

Open the contributing guide

Research direction

Start by reading the linked CVE JSON 5.0 changes article and comparing its fields with Dependency-Track's current vulnerability-data handling. Determine whether the format affects current behavior and document concrete improvement opportunities; if implementation is warranted, split or retitle this investigation as an implementation issue.

Written by the indexing model from the issue text.

Assessment

Tech stack
java, json
Domain
security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.