[
https://issues.apache.org/jira/browse/CAMEL-24222?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Andrea Cosentino reassigned CAMEL-24222:
----------------------------------------
Assignee: Andrea Cosentino
> Camel JBang MCP Server - Add camel_dependency_security_audit tool for CVE
> analysis
> ----------------------------------------------------------------------------------
>
> Key: CAMEL-24222
> URL: https://issues.apache.org/jira/browse/CAMEL-24222
> Project: Camel
> Issue Type: Improvement
> Components: camel-jbang
> Reporter: Andrea Cosentino
> Assignee: Andrea Cosentino
> Priority: Major
>
> Add a new MCP tool that performs deep CVE analysis of transitive dependencies
> in a Camel project. Distinct from camel_dependency_check (which checks
> dependency resolution) and camel_security_advisories (which lists Camel
> CVEs), this tool scans the full dependency tree for known vulnerabilities.
> Scope:
> - New tool: camel_dependency_security_audit
> - Input: project path or pom.xml location
> - Output: list of CVEs found in transitive dependencies, severity, affected
> artifact, fixed version (if available), whether the vulnerable code path is
> reachable from Camel
> - Leverage OSS Index, NVD, or GitHub Advisory Database
> - Flag dependencies that are reachable through Camel exposed code paths vs
> unreachable transitive deps
> Location: dsl/camel-jbang/camel-jbang-mcp/
--
This message was sent by Atlassian Jira
(v8.20.10#820010)