DependencyTrack / DependencyTrack/dependency-track

Project policy analysis notifications aren't very informative

Open
#1,328 0 comments 1 reaction 0 assignees View on GitHub
enhancement
Dominant language
Java
Stars
4.2k
Forks
811
Avg merge
8h 39m
Merged PRs (30d)
237

Description

### Current Behavior:
Currently, if I make a policy analysis on a given component in a project (and the audit notifications are turned on), I receive the following notification:
![image](https://user-images.githubusercontent.com/96793624/149382364-f93c3d6b-488b-407a-a805-3344a440bebd.png)
Note, in the above case, this is the decision point made:
![image](https://user-images.githubusercontent.com/96793624/149383462-bf250994-3a9d-4356-87e3-5ea54d3c01d8.png)

It's nice to get the notification, but it doesn't really tell me much (it's too general). I don't know what project this was for, what component, etc.

### Proposed Behavior:
Ideally, I think it would probably make since for this type of update to have it's own template, so that only information relevant to a policy analysis change is presented in the notification. However, a good first step (temp change) would be to at least make sure the project and component information show on these types of audit change notifications so the people being notified at least have more information to work with.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.