DependencyTrack / DependencyTrack/dependency-track

Portfolio Access Control: Wildcard Exclusion and/or Exclusion List (to enable "shaming")

Open
#1,978 1 comment 1 reaction 0 assignees View on GitHub
enhancement
Dominant language
Java
Stars
4.2k
Forks
811
Avg merge
8h 39m
Merged PRs (30d)
237

Description

Currently there is only an inclusion based Portfolio Access Control. However my client thinks that for the enterprise it is best if you can see peer-projects so that everyone is incentivized to have non-vulnerable and audited Projects driven by shame and competition.

And I concur with this analysis and agree with his logic.
Only sensitive Projects would need to be excluded to a given Portfolio

### Current Behavior:

Inclusion List of Projects to be included in the Portfolio of a given Team

### Proposed Behavior:
Exclusion List of Projects to be excluded in the Portfolio of a given Team. Default: included

Contributor guide

Open the contributing guide

Research direction

The issue names no files, tests, or entry points. Start by locating the existing inclusion-based Portfolio Access Control and determine how a Team's project list is evaluated. Define how an exclusion list and its default-included behavior should interact with the current model before implementing and testing the proposed behavior.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
authorization
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.