DependencyTrack / dependency-track

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
https://dependencytrack.org/
Apache License 2.0
2.43k stars 529 forks source link

CBOM: Add CycloneDX v1.6 support for cryptographic assets #3145

Open stevespringett opened 8 months ago

stevespringett commented 8 months ago

Current Behavior

Currently, Dependency-Track does not support cryptographic assets.

Proposed Behavior

Add support for cryptographic assets and their dependencies once CycloneDX v1.6 is released.

NOTE: May be able to reach out to IBM Quantum for a git patch or PR, as they've performed an internal fork of DT that adds support for some of these things already.

Checklist

n1ckl0sk0rtge commented 3 weeks ago

@stevespringett @VinodAnandan could you assign this issue to me, would like to work on it.

FYI @san-zrl