DependencyTrack / dependency-track

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
https://dependencytrack.org/
Apache License 2.0
2.71k stars 579 forks source link

Populate Manufacturer field in downloaded SBOM's #3935

Open thompson-tomo opened 4 months ago

thompson-tomo commented 4 months ago

Current Behavior

Property is not included

Proposed Behavior

When a SBOM is generated by Dependency track the manufacturer property as defined in (https://github.com/CycloneDX/specification/blob/62a669075f1897193a14060e0784e6a7576b693d/schema/bom-1.6.schema.json#L677) should be populated with information about OWASP or General Company information defined at a central point. The scenario depends on what the intended use of that field is.

Checklist

PiyushVyas13 commented 1 month ago

Hi @thompson-tomo . I would love to contribute to this. Can you please assign it to me?

msymons commented 1 month ago

@PiyushVyas13, I just want to check... are you wanting to work on this issue as a Hacktoberfest contribution?

PiyushVyas13 commented 1 month ago

Yes. It is actually my first time contributing to an open source project, so I'm looking forward to working on this issue

msymons commented 1 month ago

@PiyushVyas13 , first time contributing to OSS? We are honored that you chose our project to be your first.

Welcome aboard, and have fun with Hackoberfest