-
-
Notifications
You must be signed in to change notification settings - Fork 657
Open
Labels
Description
Current Behavior
Define a policy with condition:
{
"subject": "PACKAGE_URL",
"operator": "IS_NOT",
"value": "pkg:maven/com.mysql/[email protected]"
}
Upload a bom:
{
"bomFormat": "CycloneDX",
"specVersion": "1.5",
"version": 1,
"components": [
{
"type" : "library",
"group" : "com.mysql",
"name" : "mysql-connector-j",
"version" : "8.0.33",
"purl" : "pkg:maven/com.mysql/[email protected]?type=jar"
}
]
}
Observe that the policy is not triggered.
Expected Behavior
I don't think the behaviour is documented anywhere.
Yet I think it's reasonable to expect IS
/IS_NOT
operator requires equality, not being a substring.
Dependency-Track Version
4.13.2
Dependency-Track Distribution
Container Image
Database Server
PostgreSQL
Database Server Version
No response
Browser
N/A
Checklist
- I have read and understand the contributing guidelines
- I have checked the existing issues for whether this defect was already reported