Prepare Your Component for ODG¶

This guide is for component authors who want to get the most out of ODG scanning. By adding a small set of OCM labels to your component descriptor, you can control scan behaviour, ensure findings are routed to the right team, and provide context that helps ODG produce more accurate results.

Prerequisites¶

  • An OCM component descriptor (component-descriptor.yaml or equivalent)

  • Familiarity with the OCM label format

Declare Responsible Owners¶

Add the odg.ocm.software/responsibles label so that ODG and the issue replicator know whom to assign findings to.

labels:
  - name: odg.ocm.software/responsibles
    version: v1
    value:
      - type: githubTeam
        teamname: my-org/my-team

See the label reference for all supported types (githubUser, codeowners, etc.).

Note

The responsibles extension can override or extend these assignments at runtime via configurable rules. See Overwriting OCM component responsibles for details.

Provide Risk Profile Context¶

Add the security.ocm.software/risk-profile label to describe the deployment context of your component. ODG uses this to suggest adjusted CVE severity scores that reflect actual exposure rather than the theoretical maximum.

labels:
  - name: security.ocm.software/risk-profile
    version: v1
    value:
      network_exposure: "private"
      authentication_enforced: true
      user_interaction: "end-user"
      confidentiality_requirement: "low"
      integrity_requirement: "high"
      availability_requirement: "high"

Only set the fields that are meaningful for your component; omitted fields are treated as unknown and do not affect rescoring. See the label reference for all fields and allowed values.

Skip Binary or Source Scans¶

You can configure whether ODG should run binary vulnerability scans or SAST (Static Application Security Testing) source analysis. Usually skip is set when the pipeline already ran the equivalent scan.

labels:
  - name: odg.ocm.software/binary-scan-policy
    version: v1
    value:
      policy: "skip"
      comment: "Scanned upstream, results attached as SBOM"
  - name: odg.ocm.software/source-scan-policy
    version: v1
    value:
      policy: "skip"
      comment: "We use gosec for SAST scanning, see attached log"

See the label reference for all fields and allowed values.