DependencyTrack / DependencyTrack/dependency-track
Create Component Inventory from NVD CPE Dictonary
- Dominant language
- Java
- Stars
- 4.2k
- Forks
- 811
- Avg merge
- 8h 39m
- Merged PRs (30d)
- 237
Description
Current Status:
If I create a component or import a list of components I will have the issue that from time to time my vendorname or productname does not fit the NVD writing, or i cant provide a cpe to do an exact matching.
Improvement:
You could take the NVD CPE Dictonary file and parse the components listed in this file as Base Component List.
This would give the ability to choose from those components - you could see it as an input validation lite.
In this case I don't have to mind if a component without does really have no vulnerabilities or could just not be found. The system tell me I cant find this in my list maybe you should take a closer look.
Contributor guide
Research direction
The issue names no files, tests, or entry points. Start by locating the component import and NVD CPE handling, then define how the CPE dictionary becomes a selectable base list and how missing matches are reported.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100