DependencyTrack / DependencyTrack/dependency-track

Whitelist runtime packages

Open
#4,944 0 comments 0 reactions 0 assignees View on GitHub
enhancement
Dominant language
Java
Stars
4.2k
Forks
811
Avg merge
8h 39m
Merged PRs (30d)
237

Description

### Current Behavior

Hello,

My organization uses Dependency Track in the context of .Net development. We have recurring vulnerabilities in our project analyses that are due to packages that are part of the .Net runtime (e.g. System.Security.Cryptography.Xml). Those alerts are not useful to our developers because they cannot address them directly and they actually concern our infrastructure team. This team is in charge of maintaining the servers, including the upgrade of the runtime, and they have their own set of tools for detecting this kind of issue.

### Proposed Behavior

I would like the possibility to define in Dependency Track a list of package names that, like internal components, are excluded from the analyses in order to reduce the noise in the Dependency Track analyses.

### Checklist

- [x] I have read and understand the [contributing guidelines](https://github.com/DependencyTrack/dependency-track/blob/master/CONTRIBUTING.md#filing-issues)
- [x] I have checked the [existing issues](https://github.com/DependencyTrack/dependency-track/issues) for whether this enhancement was already requested

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.