Skip to content

CBOM: Add CycloneDX v1.6 support for cryptographic assets #3145

@stevespringett

Description

@stevespringett

Current Behavior

Currently, Dependency-Track does not support cryptographic assets.

Proposed Behavior

Add support for cryptographic assets and their dependencies once CycloneDX v1.6 is released.

  • Display cryptographic assets in inventory
  • Display cryptographic assets in dependency graph
  • Display cryptographic-specific fields in component view and modal dialogs
  • Add support for dependency types (display on dependency graph)

NOTE: May be able to reach out to IBM Quantum for a git patch or PR, as they've performed an internal fork of DT that adds support for some of these things already.

Checklist

Metadata

Metadata

Assignees

Labels

cdx-1.6Related to CycloneDX specification v1.6enhancementNew feature or requestp2Non-critical bugs, and features that help organizations to identify and reduce risk

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions