DependencyTrack / DependencyTrack/dependency-track

Create Component Inventory from NVD CPE Dictonary

Open
#477 1 comment 2 reactions 0 assignees View on GitHub
enhancement p2
Dominant language
Java
Stars
4.2k
Forks
811
Avg merge
8h 39m
Merged PRs (30d)
237

Description

Current Status:
If I create a component or import a list of components I will have the issue that from time to time my vendorname or productname does not fit the NVD writing, or i cant provide a cpe to do an exact matching.

Improvement:
You could take the NVD CPE Dictonary file and parse the components listed in this file as Base Component List.
This would give the ability to choose from those components - you could see it as an input validation lite.
In this case I don't have to mind if a component without does really have no vulnerabilities or could just not be found. The system tell me I cant find this in my list maybe you should take a closer look.

Contributor guide

Open the contributing guide

Research direction

The issue names no files, tests, or entry points. Start by locating the component import and NVD CPE handling, then define how the CPE dictionary becomes a selectable base list and how missing matches are reported.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.