dependency-track
dependency-track copied to clipboard
Policy: Add support for BOM in policy conditions
Extend functionality implemented in #83 to support BOM (CycloneDX, SPDX, spec versions, signed/unsigned, etc) in policy conditions.
May require https://github.com/CycloneDX/cyclonedx-core-java/issues/68
In order to make this useful we will need to first implement project-level policies per #2130.
Implementing signature verification would also require additional work to be carried our within DT.