dependency-track icon indicating copy to clipboard operation
dependency-track copied to clipboard

Add VEX Support for Rejected

Open msymons opened this issue 2 years ago • 0 comments

Current Behavior

CycloneDX 1.5 adds support for a new date field to record when (if) a vulnerability has been Rejected. See specification issue 168. ie, if field is not present then vulnerability has not been rejected!

An example of a rejected vulnerability is CVE-2021-23334.

Dependency-Track does not currently support handling this field.

Proposed Behavior

Update VEX handling in DT to support rejected timestamp. This would apply to VEX export and import,

Checklist

msymons avatar Jun 07 '23 16:06 msymons