DependencyTrack / DependencyTrack/dependency-track
Threats: Attribution and Timestamping
- Dominant language
- Java
- Stars
- 4.2k
- Forks
- 811
- Avg merge
- 8h
- Merged PRs (30d)
- 233
Description
### Current Behavior:
Dependency-Track does not provide information on the source of the data for a threat. Neither does it provide timestamps so that one can see when a threat was first identified or when it was introduced into a project.
### Proposed Behavior:
1) Provide attribution information for threats. ie, OSS Index, NPM, Internal,VulnDB, etc.
Attribution information would be useful when tracking down the source of false positives or negatives.
2) Provide timestamp information for threat identification and introduction. These timestamps are already provided in alerts... but not recorded.
Time-stamping would complement attribution info, but also help a lot with general triaging/ management.
* Work out response time for triaging.
* See specific dates for when "old" threats are being introduced into projects. Or vice versa... sometimes one might think that a threat had already been resolved once in a project but the timestamp could say otherwise... that it was introduced (say) 18 months ago.
Contributor guide
Assessment
This issue has not been assessed yet.