Skip to content

Add "Black Duck" as advisor for known security vulnerabilities #8739

@fviernau

Description

@fviernau

Black Duck amongst others is a data source for security vulnerabilities.
Goal of this ticket is to make that data source available by integrating Black Duck as a so called advisor into ORT.

Out of scope: Any other capability Black Duck has besides the security vulnerabilities,
such as scanning, e.g. for code snippets.

There is no public Black Duck instance, and the REST API docs seem to be available only via the actual instance, see also 1.

Sub-issues

Metadata

Metadata

Assignees

No one assigned

    Labels

    advisorAbout the advisor tool

    Projects

    Status

    Q1 2025 - Jan-Mar

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions