dependency-track icon indicating copy to clipboard operation
dependency-track copied to clipboard

VIEW_PORTFOLIO permissions ability to download the SBOM

Open webmutation opened this issue 3 years ago • 1 comments

Current Behavior

Hello Currently to enable users to download the SBOM image

We have to grant them PORTFOLIO_MANAGEMENT permission, this has a lot of privileges, namely the ability to delete a project, etc... that we do not want to grant to read only viewers. They may need to download the SBoM for report purposes, but that is the only operation they are required.

Proposed Behavior

Allow VIEW_PORTFOLIO to download the SBOM (enable the SBOM button to be visible).

This will allow us to enforce least privilege access principle.

Checklist

webmutation avatar Dec 16 '22 10:12 webmutation

VIEW_PORTFOLIO should grant permission to download the "Inventory" BOM VIEW_VULNERABILITY should additionally grant permission to download the "Inventory with Vulnerabilities" and "VDR" variants

msymons avatar Jan 03 '23 20:01 msymons

@msymons , Is the issue still open to work?

mohitlakhera avatar Oct 03 '25 13:10 mohitlakhera