DependencyTrack / DependencyTrack/dependency-track
Support independent policy evaluation
Open
enhancement
p3
size/M
- Dominant language
- Java
- Stars
- 4.2k
- Forks
- 811
- Avg merge
- 8h 39m
- Merged PRs (30d)
- 237
Description
Policy evaluation is currently tightly bound to the vulnerability analysis and is performed after vuln analysis upon bom upload and component added and on a scheduled basis.
It might be useful to have an external endpoint available to allow policy evaluation of one or more policies for a specific project or multiple projects.
We could additionally have an endpoint to trigger policy evaluation for the whole portfolio. We could have escalated privileges enabled for this endpoint to ensure that it is not misused.
Contributor guide
Assessment
This issue has not been assessed yet.