DependencyTrack / dependency-track

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
https://dependencytrack.org/
Apache License 2.0
2.43k stars 529 forks source link

NPE when importing SaaSBOM #1790

Closed stevespringett closed 1 year ago

stevespringett commented 1 year ago

When importing a BOM containing only services (such as a SaaSBOM), DT throws a NPE.

Currently, DT assumes a BOM will always have components, thus resulting in an NPE.

github-actions[bot] commented 1 year ago

This thread has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.