DependencyTrack / DependencyTrack/frontend

Display NVD API Attribution Notice

Open
#746 1 comment 0 reactions 0 assignees View on GitHub
defect in triage
Dominant language
Vue
Stars
171
Forks
250
Avg merge
10h 56m
Merged PRs (30d)
84

Description

### Current Behavior

This issue is a parent of [dependency-track#3294](https://github.com/DependencyTrack/dependency-track/issues/3294)

Since Dependency Track use NVD Rest API (with the APIKEY provided by the deployer) the product Dependency Track should have to respect the [Terms of Use of the NVD API](https://nvd.nist.gov/developers/terms-of-use) and display somewhere the required notice

This product uses the NVD API but is not endorsed or certified by the NVD.

OWASP Dependency Check had the same issue : [DependencyCheck#6105](https://github.com/jeremylong/DependencyCheck/issues/6105)

### Steps to Reproduce

Browse the available documentation on the website: no notice
google search prompt : site:https://docs.dependencytrack.org/ "This product uses the NVD API but is not"

No notice on the about dialog in v 4.10.0 the NVD appears in the DATASOURCE PROVIDERS but without the notice.

### Expected Behavior

The NVD terms of use should be respected.

### Dependency-Track Frontend Version

4.7.x

### Browser

Google Chrome

### Browser Version

_No response_

### Operating System

Windows

### Checklist

- [X] I have read and understand the [contributing guidelines](https://github.com/DependencyTrack/dependency-track/blob/master/CONTRIBUTING.md#filing-issues)
- [X] I have checked the [existing issues](https://github.com/DependencyTrack/frontend/issues) for whether this defect was already reported

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by checking the available documentation and the frontend About dialog, including the DATASOURCE PROVIDERS section, where the issue reports that NVD is named without the required notice. Done means the specified NVD attribution notice is displayed in the relevant product-facing location and is also present where the documentation currently describes the product.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, frontend
Issue type
Feature
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.