Trying to figure out if there is a way to use this offline #1025
Unanswered
FearTheBadger
asked this question in
Q&A
Replies: 1 comment 1 reply
-
Dependency-Track does not currently support the parsing and processing of the vulnerability extension. This is an optional capability of CycloneDX and is not part of the core specification. If this capability is required, I would recommend creating a PR that implements the functionality. |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
I have BoM's that are created in the cycloneDX format (I've tried 1.1 &1.2 if that matters), which contain all the of the vulnerability reports I need for what I am working on.
In the example xml file, found below, I get 48 findings when running the current external checks. When I turn all those external checks off to try and get the single reported finding, I get zero findings. Which tells me that when this file is ingested the vulnerabilities section is ignored.
I understand this is not ideal (especially with this super old file), but I have a need to maintain a moment in history recording of these findings in an offline environment.
Is it possible to get DT to understand this BoM and report just the findings reported in the file?
Thanks,
Brock
example BoM:
Beta Was this translation helpful? Give feedback.
All reactions