Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Currently Dependency Track removes 'properties' -fields from the uploaded sbom-file's 'component' -items. Could this be changed? #4170

Open
2 tasks done
ilarikilkki opened this issue Sep 24, 2024 · 1 comment
Labels

Comments

@ilarikilkki
Copy link

Current Behavior

In our case we have included the file paths of various components into the 'properties' -field of each component in the sbom-file.

example1

After uploading the sbom-file to DT and downloading the file back, the 'properties' -fields have been removed from it.

example2

Proposed Behavior

Do not remove 'properties' -fields from uploaded sbom-files. Having the option to view the contents of 'properties' -fields in Dependency Track's User Interface next to the found vulnerabilities would make it a lot easier to locate the vulnerable dependencies in our repositories.

Checklist

@ilarikilkki ilarikilkki added the enhancement New feature or request label Sep 24, 2024
@nscuro
Copy link
Member

nscuro commented Sep 24, 2024

What version of DT are you using? Support for component properties was added in v4.11.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants