DependencyTrack / DependencyTrack/dependency-track
Investigate Impact/Utility of CVE JSON 5.0 to Dependency-Track
- Dominant language
- Java
- Stars
- 4.2k
- Forks
- 811
- Avg merge
- 9h 4m
- Merged PRs (30d)
- 229
Description
From [Changes Coming to CVE Record Format JSON and CVE List Content Downloads](https://www.cve.org/Media/News/item/news/2022/01/11/Changes-Coming-to-CVE-Record):
> CVE JSON 5.0 is a major upgrade to JSON 4.0 that further normalizes and enriches how CVE information is presented. It adds several new data fields to CVE Records. In addition to the required data of CVE ID number, affected product(s), affected version(s), and public references, JSON 5.0 CVE Records will now include optional data such as severity scores, credit for researchers, additional languages, affected product lists, additional references, ability for community contributions, etc. This optional data will enhance CVE Records for both downstream users and the overall vulnerability management community.
Will this impact Dependency-Track or (better still) provide opportunity for improving Dependency-Track?
If the answer is "yes" then this issue can be changed from "investigate" to "implement something" (or a new issue created).
Contributor guide
Research direction
Start by reading the linked CVE JSON 5.0 changes article and comparing its fields with Dependency-Track's current vulnerability-data handling. Determine whether the format affects current behavior and document concrete improvement opportunities; if implementation is warranted, split or retitle this investigation as an implementation issue.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java, json
- Domain
- security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100