dependency-check / dependency-check/DependencyCheck

Feedback from OSSF: Can we discuss reconsidering a feature like PR 298

Open
#2,958 1 comment 0 reactions 0 assignees View on GitHub
enhancement
Dominant language
Java
Stars
7.7k
Forks
1.4k
Avg merge
9d 22h
Merged PRs (30d)
13

Description

**Story:**
As a security team, we want discovery tools which can identify the software running on an end point/workload (container/VM/Physical system etc..), and map the software version with impacted CVEs. In order to do that we would like orgs/vendor the ability/option to be able to embeds Unique Software identifiers such as CPEs or PURL in the binary/package.

There has been a PR already raised before and is being discussed in the Linux Foundation's OSSF Vulnerability disclosure working group. https://github.com/jeremylong/DependencyCheck/pull/298

If you are interested, please visit the working group to discuss as we can help the project as well: https://github.com/ossf/wg-vulnerability-disclosures

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.