DependencyTrack / DependencyTrack/dependency-track

Threats: Attribution and Timestamping

Open
#640 2 comments 0 reactions 0 assignees View on GitHub
enhancement p2
Dominant language
Java
Stars
4.2k
Forks
811
Avg merge
8h
Merged PRs (30d)
233

Description

### Current Behavior:
Dependency-Track does not provide information on the source of the data for a threat. Neither does it provide timestamps so that one can see when a threat was first identified or when it was introduced into a project.

### Proposed Behavior:
1) Provide attribution information for threats. ie, OSS Index, NPM, Internal,VulnDB, etc.

Attribution information would be useful when tracking down the source of false positives or negatives.

2) Provide timestamp information for threat identification and introduction. These timestamps are already provided in alerts... but not recorded.

Time-stamping would complement attribution info, but also help a lot with general triaging/ management.

* Work out response time for triaging.
* See specific dates for when "old" threats are being introduced into projects. Or vice versa... sometimes one might think that a threat had already been resolved once in a project but the timestamp could say otherwise... that it was introduced (say) 18 months ago.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.