DependencyTrack / DependencyTrack/dependency-track

Display GHSA affected/patched versions

Open
#1,410 1 comment 0 reactions 0 assignees View on GitHub
enhancement p2
Dominant language
Java
Stars
4.2k
Forks
811
Avg merge
8h 39m
Merged PRs (30d)
237

Description

Show affected and fixed version ranges for GitHub Advisory vulnerabilities.

### Current Behavior:

In Dependency Track v4.4, GHSA vulnerability details (e.g. overview, references) are shown, but the information about affected and patched/fixed version is missing. For instance, [GHSA-mv2r-q4g5-j8q5](https://github.com/advisories/GHSA-mv2r-q4g5-j8q5) is currently shown like this:

![image](https://user-images.githubusercontent.com/139133/154791235-b5b6a5f0-e8f1-4737-a12c-a9e69adb6c07.png)

Note that it is not clear which version of `Microsoft.Data.OData` the issue is about, or which version includes the fix.

### Proposed Behavior:

Display the affected and fixed/patched versions inside Dependency Track UI, similar to https://github.com/advisories/GHSA-mv2r-q4g5-j8q5:

![image](https://user-images.githubusercontent.com/139133/154791318-268ec728-1927-40d4-bb3e-7b45861a7910.png)

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.