Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Make components page default show all components #3719

Open
2 tasks done
starfishfive opened this issue May 16, 2024 · 3 comments · May be fixed by #3720
Open
2 tasks done

Make components page default show all components #3719

starfishfive opened this issue May 16, 2024 · 3 comments · May be fixed by #3720
Labels
enhancement New feature or request

Comments

@starfishfive
Copy link

Current Behavior

Displays No matching records found

This is a dealbreaker to comply with CIS Control 16.4

Proposed Behavior

Show a list of all components.

Checklist

@starfishfive starfishfive added the enhancement New feature or request label May 16, 2024
@starfishfive starfishfive linked a pull request May 16, 2024 that will close this issue
5 tasks
@valentijnscholten
Copy link
Contributor

I agree that the search on the Components page is very limited and could use some improvements. But what exact use-case can you currently not perform good enough to comply with CIS Control 6.4? Dependency Track does exactly what is stated in the requirements:

Establish and manage an updated inventory of third-party components used in development, often referred to as a “bill of materials,” as well as components slated for future use. This inventory is to include any risks that each third-party component could pose. Evaluate the list at least monthly to identify any changes or updates to these components, and validate that the component is still supported.

@starfishfive
Copy link
Author

@valentijnscholten I would like the posibility to go trough the complete list, to insure that each component has:

  1. Risk associated with component (Risk Score)
  2. Whether component is supported (Version/Latest Version) - Future enhancement add depecrated true/false column?

As stated by the CIS assessment specification of safeguard 16.4

@rknj
Copy link

rknj commented Aug 1, 2024

We're also interested into having a way to show all the components (across all projects) to manage the outdated libraries at a higher level.
As dependency-track force us to create a project for each couple Repository/Branch it also means we'll need a way to filter out some projects from this list.

@rknj rknj mentioned this issue Aug 2, 2024
2 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants