Skip to content

Where are product components in DefectDojo? #11715

You must be logged in to vote

Initially Defect Dojo was invented as a tool to manage Pentests (engagements) per product. These pentests weren't really split up by subsystem or API or frontend. I believe this is the reason the model is Product. And later on Product Type was added to group products together. What I've been doing in the past is using Product Types for Systems and Products for subsystems. I didn't have any use cases that didn't fit in this model. But it might be impractical if you have lots of microservices. For microservices within the same Product there is the Finding.service field. This can be used to import multiple scans for different microservices into the same Test.

For v3.0 an overhaul of the mode…

Replies: 2 comments 2 replies

You must be logged in to vote
1 reply
@aleks-liu

Answer selected by aleks-liu

You must be logged in to vote
1 reply
@aleks-liu

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants