Add configurable source of discovery for vulnerabilities - #7117
Open
heyiamwahab236 wants to merge 1 commit into
Open
heyiamwahab236 wants to merge 1 commit into
heyiamwahab236 wants to merge 1 commit into
Conversation
Organizations documenting their own vulnerabilities often need to record where a vulnerability was discovered - a penetration test, an internal audit, a bug bounty report. There is currently no field for this. Adds an optional sourceOfDiscovery attribute to Vulnerability, populated from an admin-configurable list of sources. The list is managed via GET/PUT /v1/customization/vulnerability-source and stored as a single config property. The feature is off by default; when disabled, nothing changes for existing workflows. The SOURCE_OF_DISCOVERY column is created automatically by the schema generator, consistent with how new attributes are added elsewhere. Signed-off-by: Abdul wahab Shah <214828401+heyiamwahab236@users.noreply.github.com>
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
3 tasks
Up to standards ✅🟢 Issues
|
| Metric | Results |
|---|---|
| Complexity | 24 |
NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.
2 tasks
Author
|
Companion frontend PR: DependencyTrack/frontend#1776 |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Organizations documenting their own vulnerabilities often need to record where a
vulnerability was discovered — a penetration test, an internal audit, a bug bounty
report. There is currently no field for this.
Adds an optional
sourceOfDiscoveryattribute toVulnerability, populated from anadmin-configurable list of sources. The list is managed via
GET/PUT
/v1/customization/vulnerability-sourceand stored as a single configproperty. The feature is off by default; when disabled, nothing changes for existing
workflows.
Addressed Issue
fixes #7115
Additional Details
SOURCE_OF_DISCOVERYcolumn is created automatically by the schema generator,consistent with how new attributes are added elsewhere.
/v1/customizationfacade resource for curated, validated accessto these settings; the read endpoint requires only VIEW_PORTFOLIO so the create/edit
forms can consume it. The same rows remain accessible via
/v1/configProperty.CustomizationResourcefile with their own endpoints — whichever lands later will berebased to merge the endpoints into the shared resource.
Checklist
This PR fixes a defect, and I have provided tests to verify that the fix is effectiveThis PR introduces changes to the database model, and I have updated the migration changelog accordinglyThis PR is a substantial change (per the ADR criteria), and I have added an ADR underdocs/adr/