Importing CycloneDX BOM #6052
Unanswered
software-testing-professional
asked this question in
Q&A
Replies: 1 comment 1 reply
-
Which version of CyclonDX do you use? Since 1.4, the spec support findings directly in the report. |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
I created a CycloneDX file using 'OSS review toolkit'.
When I import the CycloneDX file into DefectDojo, it results in ''CycloneDX Scan processed a total of 0 findings."
If I run the OSS review toolkit again and choose another report format (HTML for example), then all rule violations are shown.
As far as I understand the CycloneDX spec, findings / rule violations are not part of the BOM file.
So what should happen in DefectDojo, if a CycloneDX BOM is imported?
Appreciate your help! :-)
Best regards, Michael
Beta Was this translation helpful? Give feedback.
All reactions