BOM downloads default to "SNAPSHOT" version when project version is unassigned #4112
Closed
2 tasks done
Labels
defect
Something isn't working
good first issue
Good for newcomers
p3
Nice-to-have features
size/S
Small effort
Milestone
Current Behavior
When downloading BOMs via Dependency-Track's frontend (Components > Download BOM) and no version is assigned to the project (Project Details > Version), the generated CycloneDX document defaults to the version
SNAPSHOT
inmetadata.component.version
, e.g.:Steps to Reproduce
metadata.component.version
to confirm that the version is set toSNAPSHOT
.Expected Behavior
If no version is assigned to a project in Dependency-Track, the
metadata.component.version
field in the downloaded BOMs should be left empty. This field is optional in the CycloneDX specification.Dependency-Track Version
4.11.7
Dependency-Track Distribution
Container Image
Database Server
PostgreSQL
Database Server Version
15.8
Browser
Google Chrome
Checklist
The text was updated successfully, but these errors were encountered: