Importing CycloneDX BOM #6052
Unanswered
software-testing-professional
asked this question in
Q&A
Replies: 1 comment 1 reply
-
Which version of CyclonDX do you use? Since 1.4, the spec support findings directly in the report. |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
I created a CycloneDX file using 'OSS review toolkit'.
When I import the CycloneDX file into DefectDojo, it results in ''CycloneDX Scan processed a total of 0 findings."
If I run the OSS review toolkit again and choose another report format (HTML for example), then all rule violations are shown.

As far as I understand the CycloneDX spec, findings / rule violations are not part of the BOM file.
So what should happen in DefectDojo, if a CycloneDX BOM is imported?
Appreciate your help! :-)
Best regards, Michael
Beta Was this translation helpful? Give feedback.
All reactions