DependencyTrack / DependencyTrack/dependency-track

Support independent policy evaluation

Open
#6,197 0 comments 0 reactions 0 assignees View on GitHub
enhancement p3 size/M
Dominant language
Java
Stars
4.2k
Forks
811
Avg merge
8h 39m
Merged PRs (30d)
237

Description

Policy evaluation is currently tightly bound to the vulnerability analysis and is performed after vuln analysis upon bom upload and component added and on a scheduled basis.

It might be useful to have an external endpoint available to allow policy evaluation of one or more policies for a specific project or multiple projects.
We could additionally have an endpoint to trigger policy evaluation for the whole portfolio. We could have escalated privileges enabled for this endpoint to ensure that it is not misused.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.