dependency-track icon indicating copy to clipboard operation
dependency-track copied to clipboard

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.

Results 588 dependency-track issues
Sort by recently updated
recently updated
newest added

The `/v1/vulnerability/component/{ident}` endpoint allows the specifying a hash or component uuid to retrieve the vulnerabilities. Enhance this endpoint to support Package URL. Also, enhance this endpoint to support non-tracked components...

enhancement
p2

### Current Behavior: User logs in with OpenID for the first the time via Azure Active Directory. The 'OpenID Connect Users' page on DT shows user has been created, but...

in triage

It would be useful for automation if projects could be tagged on BOM upload. ### Current Behavior: Currently, when uploading BOMs via `PUT /v1/bom`, we can specify the following properties:...

enhancement
p2

### Discussed in https://github.com/DependencyTrack/dependency-track/discussions/1597 Originally posted by **software-testing-professional** May 10, 2022 We use Dependency-Track for open source license clearing. A configured license whitelist contains a bunch of open source licenses,...

### Current Behavior: * SPDX support was removed for technical (and other) reasons from prior versions of DT * SPDX currently does not describe what something is, only what something...

enhancement
help wanted
on hold
p2

### Current Behavior: A new Dependency Track project was created (using the jenkins plugin). The BOM file is the same as a another project. The other project shows 22 vulnerabilities...

in triage

### Current Behavior: When configuring a webhook notification publisher for the NEW_VULNERABILITY group with Notification Level WARNING, notifications are published with INFORMATIONAL level. ![image](https://user-images.githubusercontent.com/62144407/172935238-855f84ea-a312-4dc6-bde5-bff49f6a0884.png) ### Steps to Reproduce: ![image](https://user-images.githubusercontent.com/62144407/172934959-6ed324b5-62be-46d5-9cda-6f1026bc6646.png) ###...

help wanted
p3
good first issue

Hello I am new to this tool and I tried to install it on one of my VM having enough ram and cpu for dtrack to work. Containers are working...

question

The enhancement may already be reported! Please search for the enhancement before creating one. ### Current Behavior: Currently many tasks use hardcoded URLs, such as the MavenMetaAnalyzer or OssIndexAnalysisTask. In...

enhancement

### Current Behavior: While browsing `/projects?tag=sometag` I can see the list filtered by the tag but not the graphs in cards like Portfolio Vulnerabilities, Projects at Risk, etc... ### Proposed...

enhancement
p3