DependencyTrack / DependencyTrack/dependency-track
Whitelist runtime packages
- Dominant language
- Java
- Stars
- 4.2k
- Forks
- 811
- Avg merge
- 8h 39m
- Merged PRs (30d)
- 237
Description
### Current Behavior
Hello,
My organization uses Dependency Track in the context of .Net development. We have recurring vulnerabilities in our project analyses that are due to packages that are part of the .Net runtime (e.g. System.Security.Cryptography.Xml). Those alerts are not useful to our developers because they cannot address them directly and they actually concern our infrastructure team. This team is in charge of maintaining the servers, including the upgrade of the runtime, and they have their own set of tools for detecting this kind of issue.
### Proposed Behavior
I would like the possibility to define in Dependency Track a list of package names that, like internal components, are excluded from the analyses in order to reduce the noise in the Dependency Track analyses.
### Checklist
- [x] I have read and understand the [contributing guidelines](https://github.com/DependencyTrack/dependency-track/blob/master/CONTRIBUTING.md#filing-issues)
- [x] I have checked the [existing issues](https://github.com/DependencyTrack/dependency-track/issues) for whether this enhancement was already requested
Contributor guide
Assessment
This issue has not been assessed yet.