DependencyTrack / DependencyTrack/dependency-track
Policy condition PURL IS_NOT will match a substring
- Dominant language
- Java
- Stars
- 4.2k
- Forks
- 811
- Avg merge
- 8h 39m
- Merged PRs (30d)
- 237
Description
### Current Behavior
Define a policy with condition:
```
{
"subject": "PACKAGE_URL",
"operator": "IS_NOT",
"value": "pkg:maven/com.mysql/mysql-connector-j@8.0.33"
}
```
Upload a bom:
```
{
"bomFormat": "CycloneDX",
"specVersion": "1.5",
"version": 1,
"components": [
{
"type" : "library",
"group" : "com.mysql",
"name" : "mysql-connector-j",
"version" : "8.0.33",
"purl" : "pkg:maven/com.mysql/mysql-connector-j@8.0.33?type=jar"
}
]
}
```
Observe that the policy is not triggered.
### Expected Behavior
I don't think the behaviour is documented anywhere.
Yet I think it's reasonable to expect `IS`/`IS_NOT` operator requires equality, not being a substring.
### Dependency-Track Version
4.13.2
### Dependency-Track Distribution
Container Image
### Database Server
PostgreSQL
### Database Server Version
_No response_
### Browser
N/A
### Checklist
- [x] I have read and understand the [contributing guidelines](https://github.com/DependencyTrack/dependency-track/blob/master/CONTRIBUTING.md#filing-issues)
- [x] I have checked the [existing issues](https://github.com/DependencyTrack/dependency-track/issues) for whether this defect was already reported
Contributor guide
Assessment
This issue has not been assessed yet.