dependency-track icon indicating copy to clipboard operation
dependency-track copied to clipboard

Add Hash Comparison Analysis

Open stevespringett opened this issue 6 years ago • 2 comments

When an SBoM is uploaded and processed, compare the hashes of the component as stated in the BOM with the hashes derived from the origin repo the component was retrieved from (via Package URL), to identify modified components or potential risk of impersonated/counterfeit components of malicious intent.

stevespringett avatar Jun 13 '19 22:06 stevespringett

Should this be implemented after support is added for additional repositories (such as Sonatype's Nexus)? Otherwise, the system would not know the hashes for internal components, right?

msymons avatar Jun 17 '19 15:06 msymons

ideally, yes, after

stevespringett avatar Jun 17 '19 18:06 stevespringett