Commit graph

104 commits

Author SHA1 Message Date
Stefan Fleckenstein
d34cadc8a6 Signed-off-by: Stefan Fleckenstein <stefan@fleckenstein.co.uk> 2025-11-09 14:37:07 +00:00
Stefan Fleckenstein
bb971b38d3 SecObserve has been moved to another GitHub organisation
Signed-off-by: Stefan Fleckenstein <stefan@fleckenstein.co.uk>
2025-11-09 14:37:07 +00:00
Viktor Petersson
6705904da8
Sort list. Add sbomify.
Signed-off-by: Viktor Petersson <self@vpetersson.com>
2025-10-20 11:24:28 +01:00
nscuro
eabd376838
Add support for scheduled summary notifications
Co-authored-by: Max Schiller <msr@mm-software.com>
Co-authored-by: Marlon Gäthje <mge@mm-software.com>
Co-authored-by: Richard Bickert <rbt@mm-software.com>
Signed-off-by: nscuro <nscuro@protonmail.com>
2025-04-03 21:41:28 +02:00
Andre Schlegel-Tylla
2c094818ac
Add feature to define the test title for DefectDojo integration
New optional per project property "defectdojo.testTitle"
When property is set, the given test title will be set in DefectDojo

Signed-off-by: Andre Schlegel-Tylla <andre.schlegel-tylla@virtimo.de>
2025-03-31 15:07:07 +02:00
Thomas Schauer-Koeckeis
bf8fc68aed updated docs
Signed-off-by: Thomas Schauer-Koeckeis <thomas.schauer-koeckeis@rohde-schwarz.com>
2025-02-10 14:23:09 +01:00
Stefan Fleckenstein
ce49a80154
Add SecObserve to community integrations
Signed-off-by: Stefan Fleckenstein <stefan.fleckenstein@maibornwolff.de>
2025-01-23 16:02:52 +01:00
Niklas
85031a3dcd
Merge pull request #4547 from stevenbuccini/documentation-fixes 2025-01-15 14:28:54 +01:00
Simon A. Eugster
413594c090 docs: Clarify OpenAPI endpoint location
Signed-off-by: Simon A. Eugster <simon.eu@gmail.com>
2025-01-15 08:56:31 +01:00
Steven Buccini
a676d0afe1 Fix miscellaneous typos
While HTTP headers are case-insensitive, these changes align the examples with the rest of the documentation and source code.

Signed-off-by: Steven Buccini <steven@stevenbuccini.com>
2025-01-12 16:24:26 -05:00
Kirill.Sybin
fce382583f Remove deprecation notice and inform of risks
Remove deprecation notice for unauthenticated access to the Badge API,
as the use of API keys for authenticated access comes with risks too
that the maintainer of the DT instance has to weigh against the use of
unauthenticated access which does not use API keys.

Signed-off-by: Kirill.Sybin <kirill.sybin@lex-com.net>
2024-12-29 21:55:52 +01:00
Edouard Shaar
1170414a9b Update Azure DevOps Extension
Signed-off-by: Edouard Shaar <zarthia@gmail.com>
2024-12-01 23:41:29 -05:00
nscuro
d36a6afd0f
Update changelog for v4.12.0 with recent changes
Signed-off-by: nscuro <nscuro@protonmail.com>
2024-10-01 22:03:53 +02:00
Kirill.Sybin
02a44accb6 Update documentation
Update documentation for globally configurable unauthenticated access to
badges.

Signed-off-by: Kirill.Sybin <kirill.sybin@lex-com.net>
2024-09-29 17:32:57 +02:00
Kirill.Sybin
0e3e57623f Add default team for badges
Add a default team for viewing badges for new DBs.

Signed-off-by: Kirill.Sybin <kirill.sybin@lex-com.net>
2024-09-22 22:57:48 +02:00
Kirill.Sybin
1931654ff8 Update documentation
Signed-off-by: Kirill.Sybin <kirill.sybin@lex-com.net>
2024-09-11 22:05:21 +02:00
nscuro
68e615a1b9
Support tagging of notification rules
Supersedes #3506

Co-authored-by: Sebastien Delcoigne <sebastien.delcoigne@gmail.com>
Signed-off-by: nscuro <nscuro@protonmail.com>
2024-08-31 22:45:00 +02:00
nscuro
b9c7bb6ddb
Update REST API docs to reflect change from Swagger v2 to OpenAPI v3
Signed-off-by: nscuro <nscuro@protonmail.com>
2024-08-03 18:43:58 +02:00
Aravind Parappil
43903e724a Add Notification For BOM_VALIDATION_FAILED
If uploaded BOM is invalid, dispatches a notification with InvalidBomProblemDetails before
throwing the respective exception

Signed-off-by: Aravind Parappil <aravindparappil@gmail.com>
2024-06-01 20:48:05 -04:00
Massimo Prencipe
61e9140d8f Fix documentation
Signed-off-by: Massimo Prencipe <mprencipe@gmail.com>
2024-03-21 17:39:02 +02:00
Marlon Pina Tojal
9be9d48508 add documentation
Signed-off-by: Marlon Pina Tojal <marlont@backbase.com>
2023-12-18 10:31:56 +01:00
nscuro
b5c39485a2
Add docs for debugging missing notifications
Signed-off-by: nscuro <nscuro@protonmail.com>
2023-11-20 19:42:46 +01:00
nscuro
4f01551aa6
Add missing documentation for notification levels
Signed-off-by: nscuro <nscuro@protonmail.com>
2023-11-20 19:42:46 +01:00
rbt-mm
7a789d57b4
Add BOM_PROCESSING_FAILED notification (#2600)
* Add BOM_PROCESSING_FAILED notification

A new notification is sent if the notification rule includes the
notification group BOM_PROCESSING_FAILED and if an error happens during
the upload of a BOM.

Signed-off-by: RBickert <rbt@mm-software.com>

* Add project url and exception to new notification

Signed-off-by: RBickert <rbt@mm-software.com>

* Add BOM format and specVersion

Detach `bomProcessingFailedProject`

Rename `exception` to `cause`

Signed-off-by: RBickert <rbt@mm-software.com>

---------

Signed-off-by: RBickert <rbt@mm-software.com>
2023-03-22 20:11:36 +01:00
Lars Meijers
8e72253c01 do not reactivate flag documentation
Signed-off-by: Lars Meijers <Lars.Meijers@netcetera.com>
2023-03-03 16:39:59 +01:00
lme-nca
26e4345cb2
Fix internal technical data in aliases of FPF export (#2471)
* fix alias mapping in export

Signed-off-by: Lars Meijers <Lars.Meijers@netcetera.com>

* bumped FPF version in test

Signed-off-by: Lars Meijers <Lars.Meijers@netcetera.com>

---------

Signed-off-by: Lars Meijers <Lars.Meijers@netcetera.com>

Closes #2469
2023-02-27 16:26:46 +01:00
Mvld3r
ca750b9687 Set Jira URL for Jira notifications globally rather than in alerts
Signed-off-by: Mvld3r <Mvld3r@users.noreply.github.com>
2022-12-16 17:17:43 +01:00
rbt-mm
f6e7cc4cdc
Display version status in Audit Vulnerabilities and Exploit Predictions tab (#2272)
* Add latest version value to a finding's component

Signed-off-by: RBickert <rbt@mm-software.com>

* Add test for `component.latestVersion` in Finding

Signed-off-by: RBickert <rbt@mm-software.com>

* Add new `finding.component.latestVersion` to docs

Signed-off-by: RBickert <rbt@mm-software.com>

Signed-off-by: RBickert <rbt@mm-software.com>
2022-12-12 18:40:04 +01:00
Edouard Shaar
5d1bebba6c Add Azure DevOps Extension to community integrations
Signed-off-by: Edouard Shaar <edouard.shaar@gsoft.com>
2022-12-08 16:23:29 -05:00
Mvld3r
0ce5281a7c Add a Jira Publisher
Signed-off-by: Mvld3r <Mvld3r@users.noreply.github.com>
2022-11-16 20:57:59 +01:00
Rob Best
ebabef07f0 Add dependency-track-exporter to community-integrations.md
Signed-off-by: Rob Best <robertbest89@gmail.com>
2022-11-11 14:51:42 +00:00
nscuro
8d97b9792e
Include vulnerability aliases in notifications
Fixes #1992

Signed-off-by: nscuro <nscuro@protonmail.com>
2022-10-11 14:27:24 +02:00
nscuro
5809f32ba6
Add dtapac to community integrations
Signed-off-by: nscuro <nscuro@protonmail.com>
2022-09-16 15:32:52 +02:00
Maarten Heebink
29fecc8893 docs: Added TRIMMs Backstage plugin to community-integrations
Signed-off-by: Maarten Heebink <maarten.heebink@trimm.nl>
2022-09-14 13:53:11 +02:00
Alioune SY
f542dd3537 Restricting notification publisher to non default one and override configuration through env variable
Implemented as per https://github.com/DependencyTrack/dependency-track/pull/1760#discussion_r919259768 and https://github.com/DependencyTrack/dependency-track/pull/1760#discussion_r919268735

Signed-off-by: Alioune SY <sy_alioune@yahoo.fr>
2022-07-12 23:10:34 +02:00
Alioune SY
66e031308a Amending documentation to exhibit security warning and task to perform regarding template override
Taking into account PR review comments by @nscuro

Signed-off-by: Alioune SY <sy_alioune@yahoo.fr>
2022-07-10 20:32:22 +02:00
Alioune SY
4f7dd71c4f Make the notification template editable
Notification template enhancement as described in #275. Allow publisher metadata propagation to implementing classes (e.g. MIME type)

Signed-off-by: Alioune SY <sy_alioune@yahoo.fr>
2022-07-07 12:38:23 +02:00
Sam Li2
df19eb9a40 Add global reimport enhancement support - note this feature need corresponding frondend code change
Signed-off-by: Sam Li2 <sli2@MAC-sli.lan>
Signed-off-by: Sam Li2 <sli2@MAC-sli.local>
2022-06-23 14:33:40 -04:00
Stephan Strate
3416f8d606 Add MattermostPublisher for Mattermost notifications
Signed-off-by: Stephan Strate <s.strate@prosoz.de>
2022-06-10 17:15:46 +02:00
Niklas
d5f1126960
Merge pull request #1691 from tmehnert/add-violations-badge
Add violations badge
2022-06-09 22:35:27 +02:00
Torsten Mehnert
428770649d Update docs for badges
Signed-off-by: Torsten Mehnert <torsten.mhn@gmail.com>
2022-06-09 21:43:05 +02:00
Niklas
2dcdbf9c8c
Merge pull request #1631 from yangsec888/master
Issue #1622 DefectDojo integration reimport enhancement
2022-06-09 16:48:53 +02:00
Sam Li2
b87c45bf0f Add additoinal reimport flag per project per nscuro recommendation
Signed-off-by: Sam Li2 <sli2@MAC-sli.local>
2022-06-07 16:06:19 -04:00
Sam Li2
c96e82986b Issue #1622 DefectDojo integration reimport enhancement
Signed-off-by: Sam Li2 <sli2@MAC-sli.local>
2022-06-07 16:06:19 -04:00
nscuro
7e1fd64248
Fix cwe field names for findings API and FPF
Signed-off-by: nscuro <nscuro@protonmail.com>
2022-05-17 19:54:26 +02:00
nscuro
013252c26e
Ensure backwards-compatibility by including an additional cwe field in API objects and notifications
Addresses concerns with 3rd party integrations, e.g. https://github.com/DependencyTrack/dependency-track/issues/1467#issuecomment-1128161152

Signed-off-by: nscuro <nscuro@protonmail.com>
2022-05-17 17:37:03 +02:00
nscuro
8271594895
Update notification examples
* Add sample for `POLICY_VIOLATION`
* Correct `cwe` field for vulnerability objects

Also fix wording in changelog

Signed-off-by: nscuro <nscuro@protonmail.com>
2022-05-13 10:47:32 +02:00
Tonimir Kisasondi
9e0d95130c Documentation fix for export endpoint permissions
If you want to export the FPF format findings via the `/api/v1/finding/project/{uuid}/export` API, the documentation says that you need the VULNERABILITY_ANALYSIS permission for the accompanying API key. After some debugging, i found out that the source requires VIEW_VULNERABILITY:

beda0ce2a5/src/main/java/org/dependencytrack/resources/v1/FindingResource.java (L111)

This is a fix to patch the documentation to state the correct permissions needed.

Signed-off-by: Tonimir Kisasondi <kisasondi@gmail.com>
2022-05-12 19:41:12 +02:00
Steve Springett
6356a5125f #1467 - Refactored to support multiple CPEs per vulnerability. Breaking change on Finding API. Updated docs. Updated CPE spec to v4.6
Signed-off-by: Steve Springett <steve@springett.us>
2022-03-15 00:57:46 -05:00
Steve Springett
bca7a18d2d Added cisco webex
Signed-off-by: Steve Springett <steve@springett.us>
2022-02-15 00:17:03 -06:00