DependencyTrack / DependencyTrack/frontend
Display NVD API Attribution Notice
- Dominant language
- Vue
- Stars
- 171
- Forks
- 250
- Avg merge
- 10h 56m
- Merged PRs (30d)
- 84
Description
### Current Behavior
This issue is a parent of [dependency-track#3294](https://github.com/DependencyTrack/dependency-track/issues/3294)
Since Dependency Track use NVD Rest API (with the APIKEY provided by the deployer) the product Dependency Track should have to respect the [Terms of Use of the NVD API](https://nvd.nist.gov/developers/terms-of-use) and display somewhere the required notice
This product uses the NVD API but is not endorsed or certified by the NVD.
OWASP Dependency Check had the same issue : [DependencyCheck#6105](https://github.com/jeremylong/DependencyCheck/issues/6105)
### Steps to Reproduce
Browse the available documentation on the website: no notice
google search prompt : site:https://docs.dependencytrack.org/ "This product uses the NVD API but is not"
No notice on the about dialog in v 4.10.0 the NVD appears in the DATASOURCE PROVIDERS but without the notice.
### Expected Behavior
The NVD terms of use should be respected.
### Dependency-Track Frontend Version
4.7.x
### Browser
Google Chrome
### Browser Version
_No response_
### Operating System
Windows
### Checklist
- [X] I have read and understand the [contributing guidelines](https://github.com/DependencyTrack/dependency-track/blob/master/CONTRIBUTING.md#filing-issues)
- [X] I have checked the [existing issues](https://github.com/DependencyTrack/frontend/issues) for whether this defect was already reported
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by checking the available documentation and the frontend About dialog, including the DATASOURCE PROVIDERS section, where the issue reports that NVD is named without the required notice. Done means the specified NVD attribution notice is displayed in the relevant product-facing location and is also present where the documentation currently describes the product.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation, frontend
- Issue type
- Feature
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100