Skip to content

Enforce a max size for BOM and VEX uploads - #7545

Merged
nscuro merged 1 commit into
DependencyTrack:mainfrom
nscuro:max-upload-size
Oct 3, 2026
Merged

nscuro merged 1 commit into
DependencyTrack:mainfrom
nscuro:max-upload-size

Conversation

@nscuro

@nscuro nscuro commented Oct 3, 2026 •

Copy link
Copy Markdown
Member

Description

Enforces a max size for BOM and VEX uploads.

Addressed Issue

N/A

Additional Details

To align with ASVS 5.2, particularly 5.2.1 and 5.2.3: https://github.com/OWASP/ASVS/blob/v5.0.0/5.0/en/0x14-V5-File-Handling.md#v52-file-upload-and-content

Docs PR: DependencyTrack/docs#290

Checklist

  • I have read and understand the contributing guidelines
  • This PR fixes a defect, and I have provided tests to verify that the fix is effective
  • This PR implements an enhancement, and I have provided tests to verify that it works as intended
  • This PR introduces changes to the database model, and I have updated the migration changelog accordingly
  • This PR introduces new or alters existing behavior, and I have updated the documentation accordingly
  • This PR is a substantial change (per the ADR criteria), and I have added an ADR under docs/adr/

To align with ASVS 5.2, particularly 5.2.1 and 5.2.3: https://github.com/OWASP/ASVS/blob/v5.0.0/5.0/en/0x14-V5-File-Handling.md#v52-file-upload-and-content

Signed-off-by: nscuro <nscuro@protonmail.com>
@nscuro nscuro added this to the 5.2 milestone Oct 3, 2026
@nscuro nscuro added the enhancement New feature or request label Oct 3, 2026
@owasp-dt-bot

Copy link
Copy Markdown

✅ Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
✅ Open Source Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@codacy-production

codacy-production Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 0 complexity

Metric Results
Complexity 0

View in Codacy

🟢 Coverage 91.67% diff coverage · +0.02% coverage variation

Metric Results
Coverage variation ✅ +0.02% coverage variation (-1.00%)
Diff coverage ✅ 91.67% diff coverage (70.00%)

View coverage diff in Codacy

Coverage variation details
Coverable lines Covered lines Coverage
Common ancestor commit (fae4695) 45798 40205 87.79%
Head commit (aa97b4b) 45807 (+9) 40221 (+16) 87.81% (+0.02%)

Coverage variation is the difference between the coverage for the head and common ancestor commits of the pull request branch: <coverage of head commit> - <coverage of common ancestor commit>

Diff coverage details
Coverable lines Covered lines Diff coverage
Pull request (#7545) 12 11 91.67%

Diff coverage is the percentage of lines that are covered by tests out of the coverable lines that the pull request added or modified: <covered lines added or modified>/<coverable lines added or modified> * 100%

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@nscuro
nscuro merged commit 01e1e5b into DependencyTrack:main Oct 3, 2026
23 checks passed
@nscuro
nscuro deleted the max-upload-size branch October 3, 2026 14:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants