DependencyTrack / DependencyTrack/dependency-track

Audit Screen: Display Purl

Open
#351 0 comments 0 reactions 0 assignees View on GitHub
enhancement p2
Dominant language
Java
Stars
4.2k
Forks
811
Avg merge
8h 39m
Merged PRs (30d)
237

Description

### Current Behavior:

Vulnerability Auditing is accessible via a project's Audit tab and also via the Component screen (click on Audit mode when viewing Vulnerabilities tab).

The Audit screen does not display the Package URL (Purl) for the Component.

### Proposed Behavior:

When it's available (ie, using BOM upload rather than Dependency-Check), display a component's Purl on the Audit Screen, The Purl field should be copyable, per #350

The utility of displaying Purl on the Audit screen is to make it easier to double-check results using the OSS Index website. For instance, when a False Positive has been removed from OSS Index, this is not reflected in Dependency-Track.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.