DependencyTrack / DependencyTrack/dependency-track
Audit Screen: Display Purl
- Dominant language
- Java
- Stars
- 4.2k
- Forks
- 811
- Avg merge
- 8h 39m
- Merged PRs (30d)
- 237
Description
### Current Behavior:
Vulnerability Auditing is accessible via a project's Audit tab and also via the Component screen (click on Audit mode when viewing Vulnerabilities tab).
The Audit screen does not display the Package URL (Purl) for the Component.
### Proposed Behavior:
When it's available (ie, using BOM upload rather than Dependency-Check), display a component's Purl on the Audit Screen, The Purl field should be copyable, per #350
The utility of displaying Purl on the Audit screen is to make it easier to double-check results using the OSS Index website. For instance, when a False Positive has been removed from OSS Index, this is not reflected in Dependency-Track.
Contributor guide
Assessment
This issue has not been assessed yet.