DependencyTrack / DependencyTrack/dependency-track

Feature: Register and track vulnerabilites for internal projects (not only components)

Open
#2,028 0 comments 1 reaction 0 assignees View on GitHub
enhancement
Dominant language
Java
Stars
4.2k
Forks
811
Avg merge
8h 39m
Merged PRs (30d)
237

Description

To detect, respond, track and report to vulnerabilities that's part of customer codebase it would be beneficial if Dependency Track could handle this in a agnostic way.
This as an alternative way of registering existing vulnerabilities from BOM import as described in #1297
Se https://owasp.slack.com/archives/C6R3R32H4/p1664973336733189 for chat group discussion.

### Current Behavior:
Custom vulnerabilities can be created and registered and held internally in Dependency Track.
These can be linked to third party components as well as internal components.
The reports and audits show custom vulnerabilities registered internally.

### Proposed Behavior:
Be able to link internal vulnerabilities to project (PURL or CPE) so that these can be tracked and responded to in an agnostic way.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.