DependencyTrack / DependencyTrack/dependency-track
Portfolio Access Control: Wildcard Exclusion and/or Exclusion List (to enable "shaming")
- Dominant language
- Java
- Stars
- 4.2k
- Forks
- 811
- Avg merge
- 8h 39m
- Merged PRs (30d)
- 237
Description
Currently there is only an inclusion based Portfolio Access Control. However my client thinks that for the enterprise it is best if you can see peer-projects so that everyone is incentivized to have non-vulnerable and audited Projects driven by shame and competition.
And I concur with this analysis and agree with his logic.
Only sensitive Projects would need to be excluded to a given Portfolio
### Current Behavior:
Inclusion List of Projects to be included in the Portfolio of a given Team
### Proposed Behavior:
Exclusion List of Projects to be excluded in the Portfolio of a given Team. Default: included
Contributor guide
Research direction
The issue names no files, tests, or entry points. Start by locating the existing inclusion-based Portfolio Access Control and determine how a Team's project list is evaluated. Define how an exclusion list and its default-included behavior should interact with the current model before implementing and testing the proposed behavior.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- authorization
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 30/100