You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I don't think that Dependency Track is a good candidate to consume the CycloneDX report from grype because there doesn't seem to be support for vulnerabilities.
Syft, however, will benefit from supporting compatibility with Dependency Track because it will produce a BOM (vs. a BOM + Vulnerabilities like Grype).
The one requirement will be to use PURLs. I've opened a documentation issue in Dependency Track to update the documentation on what appears a strict dependency on PURLs and the non-support of the vulnerability extension
We should be able to use the CycloneDX report with https://dependencytrack.org/ , seeing vulnerabilities for all dependencies
The text was updated successfully, but these errors were encountered: