DependencyTrack / DependencyTrack/dependency-track
Feature: Register and track vulnerabilites for internal projects (not only components)
- Dominant language
- Java
- Stars
- 4.2k
- Forks
- 811
- Avg merge
- 8h 39m
- Merged PRs (30d)
- 237
Description
To detect, respond, track and report to vulnerabilities that's part of customer codebase it would be beneficial if Dependency Track could handle this in a agnostic way.
This as an alternative way of registering existing vulnerabilities from BOM import as described in #1297
Se https://owasp.slack.com/archives/C6R3R32H4/p1664973336733189 for chat group discussion.
### Current Behavior:
Custom vulnerabilities can be created and registered and held internally in Dependency Track.
These can be linked to third party components as well as internal components.
The reports and audits show custom vulnerabilities registered internally.
### Proposed Behavior:
Be able to link internal vulnerabilities to project (PURL or CPE) so that these can be tracked and responded to in an agnostic way.
Contributor guide
Assessment
This issue has not been assessed yet.