如何配置Dependency-Track仅发送CRITICAL级新漏洞邮件通知?
解决Dependency-Track仅发送CRITICAL级新漏洞邮件通知的问题
问题场景
我有一台Dependency-Track服务器,当前会对所有新发现的漏洞发送邮件通知,但我只希望发送严重性为CRITICAL级别的漏洞通知。我原本想在Pebble模板里实现这样的逻辑:
{% if subject.vulnerability.severity == "CRITICAL" %} // 发送通知内容 {% else %} // 不发送任何通知 {% endif %}
但使用下面的模板后,High、Medium、Minor级别的漏洞还是会触发空邮件通知,需要找到在else分支里让通知完全不发送的方法。我当前使用的模板如下:
{% if notification.group == "NEW_VULNERABILITY" %} {% if subject.vulnerability.severity == "CRITICAL" %} {{ notification.title }} -------------------------------------------------------------------------------- Vulnerability ID: {{ subject.vulnerability.vulnId }} Severity: {{ subject.vulnerability.severity }} Source: {{ subject.vulnerability.source }} Component: {{ subject.component.toString }} Component URL: {{ baseUrl }}/component/?uuid={{ subject.component.uuid }} Project: {{ subject.component.project.name }} Version: {{ subject.component.project.version }} Description: {{ subject.component.project.description }} Project URL: {{ baseUrl }}/projects/{{ subject.component.project.uuid }} {% if notification.subject.affectedProjects|length > 1%} -------------------------------------------------------------------------------- Other affected projects: {% for affectedProject in notification.subject.affectedProjects %} {% if not (affectedProject.uuid == subject.component.project.uuid) %} Project:[{{affectedProject.name}} : {{ affectedProject.version }}] Project URL:{{ baseUrl }}/project/{{ affectedProject.uuid }} {% endif %} {% endfor %} {% endif %} -------------------------------------------------------------------------------- {{ notification.content }} -------------------------------------------------------------------------------- {{ timestamp }} {% endif %} {% endif %}
解决方案
Dependency-Track的Pebble模板支持{% skip %}指令,当模板执行到这个指令时,会直接跳过整个通知的发送流程,不会生成空邮件。你需要修改模板,在判断到漏洞严重性不是CRITICAL时,执行这个指令:
修改后的完整模板如下:
{% if notification.group == "NEW_VULNERABILITY" %} {% if subject.vulnerability.severity != "CRITICAL" %} {% skip %} {% endif %} {{ notification.title }} -------------------------------------------------------------------------------- Vulnerability ID: {{ subject.vulnerability.vulnId }} Severity: {{ subject.vulnerability.severity }} Source: {{ subject.vulnerability.source }} Component: {{ subject.component.toString }} Component URL: {{ baseUrl }}/component/?uuid={{ subject.component.uuid }} Project: {{ subject.component.project.name }} Version: {{ subject.component.project.version }} Description: {{ subject.component.project.description }} Project URL: {{ baseUrl }}/projects/{{ subject.component.project.uuid }} {% if notification.subject.affectedProjects|length > 1%} -------------------------------------------------------------------------------- Other affected projects: {% for affectedProject in notification.subject.affectedProjects %} {% if not (affectedProject.uuid == subject.component.project.uuid) %} Project:[{{affectedProject.name}} : {{ affectedProject.version }}] Project URL:{{ baseUrl }}/project/{{ affectedProject.uuid }} {% endif %} {% endfor %} {% endif %} -------------------------------------------------------------------------------- {{ notification.content }} -------------------------------------------------------------------------------- {{ timestamp }} {% endif %}
逻辑说明
- 首先判断当前通知是否属于
NEW_VULNERABILITY分组 - 如果漏洞严重性不是CRITICAL,直接执行
{% skip %},终止通知发送 - 只有当严重性为CRITICAL时,才会继续渲染完整的邮件内容并发送
这样就能彻底避免非CRITICAL级漏洞触发空邮件的问题。
内容的提问来源于stack exchange,提问作者Aliou
相关产品推荐
相关产品推荐

