DependencyTrack / DependencyTrack/dependency-track
Project level recommendation to "Safer & Closest Version" or "Safest Version" to fix an existing vulnerable component version
- Dominant language
- Java
- Stars
- 4.2k
- Forks
- 811
- Avg merge
- 8h
- Merged PRs (30d)
- 233
Description
The enhancement may already be reported! Please search for the enhancement before creating one.
### Current Behavior:
Specific to SCA, Dependency-Track already supports outdated version detection. However, at the project level, when one visits the "Audit Vulnerabilities" tab, insights of the components that are vulnerable with the current version, severity, GHSA / NVD insights etc. are available but this diagnosis has limited value without any recommendation to retrofit the component. that is commonly available in most SCA tools and platforms
### Proposed Behavior:
It would be nice to have Dependency Track recommend or provide insights to the "Safer & Closest Version" or "Safest Version" for the vulnerable component version in use. This will help users with an actionable outcome as part of remediating the vulnerability rather than looking at other SCA tools and external sources on what version to upgrade / downgrade to fix the vulnerable library.
Contributor guide
Assessment
This issue has not been assessed yet.