DependencyTrack / DependencyTrack/dependency-track

New Repositories are required: Github and Sourceforge

Open
#1,840 1 comment 0 reactions 0 assignees View on GitHub
enhancement
Dominant language
Java
Stars
4.2k
Forks
811
Avg merge
8h 39m
Merged PRs (30d)
237

Description

Many of FOSS SW components we are using for your internal services are placed on Github and Sourceforge repositories.
In accordance with Standards we have to look for ALL known vulnerabilities.

### Current Behavior:
To look for CVE vulnerabilities for FOSS on Github and Sourceforge we use almost registered/available CPE strings.
But many of FOSS there may not have registered CPE and may have GHSA only.

Java, Python, etc. applications and libraries are placed on repositories like Maven, Pypi, etc.
These repositories are available in the DT and SonatypeOSS ecosystems

But apps and libraries we using are written in C/C++ and placed almost on Github and Sourceforge repositories.
Unfortunately, Github and Sourcefoge repositories are not present in the ecosystems.
So we are currently limited to use CPEs and CVEs

### Proposed Behavior:
It is necessary to add Github and Sourceforge repositories as repositories in order to look for GHSAs and actuality of Component's PURLs:
- pkg:github/protobuf/protobuf@3.21.1
- pkg:sourceforge/bzip2/bzip2@1.0.8

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.