DependencyTrack / DependencyTrack/dependency-track

Currently Dependency Track removes 'properties' -fields from the uploaded sbom-file's 'component' -items. Could this be changed?

Open
#4,170 2 comments 0 reactions 0 assignees View on GitHub
enhancement pending more information
Dominant language
Java
Stars
4.2k
Forks
811
Avg merge
8h 39m
Merged PRs (30d)
237

Description

### Current Behavior

In our case we have included the file paths of various components into the 'properties' -field of each component in the sbom-file.

![example1](https://github.com/user-attachments/assets/6ceb9672-f7ca-4e23-bcb7-0641afd63068)

After uploading the sbom-file to DT and downloading the file back, the 'properties' -fields have been removed from it.

![example2](https://github.com/user-attachments/assets/f0d9d5b9-b43c-4887-8379-29e9a02a176d)

### Proposed Behavior

Do not remove 'properties' -fields from uploaded sbom-files. Having the option to view the contents of 'properties' -fields in Dependency Track's User Interface next to the found vulnerabilities would make it a lot easier to locate the vulnerable dependencies in our repositories.

### Checklist

- [X] I have read and understand the [contributing guidelines](https://github.com/DependencyTrack/dependency-track/blob/master/CONTRIBUTING.md#filing-issues)
- [X] I have checked the [existing issues](https://github.com/DependencyTrack/dependency-track/issues) for whether this enhancement was already requested

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.