dependency-check / dependency-check/DependencyCheck
Feedback from OSSF: Can we discuss reconsidering a feature like PR 298
- Dominant language
- Java
- Stars
- 7.7k
- Forks
- 1.4k
- Avg merge
- 9d 22h
- Merged PRs (30d)
- 13
Description
**Story:**
As a security team, we want discovery tools which can identify the software running on an end point/workload (container/VM/Physical system etc..), and map the software version with impacted CVEs. In order to do that we would like orgs/vendor the ability/option to be able to embeds Unique Software identifiers such as CPEs or PURL in the binary/package.
There has been a PR already raised before and is being discussed in the Linux Foundation's OSSF Vulnerability disclosure working group. https://github.com/jeremylong/DependencyCheck/pull/298
If you are interested, please visit the working group to discuss as we can help the project as well: https://github.com/ossf/wg-vulnerability-disclosures
Contributor guide
Assessment
This issue has not been assessed yet.