DependencyTrack / DependencyTrack/dependency-track

Project level recommendation to "Safer & Closest Version" or "Safest Version" to fix an existing vulnerable component version

Open
#2,003 3 comments 3 reactions 0 assignees View on GitHub
enhancement
Dominant language
Java
Stars
4.2k
Forks
811
Avg merge
8h
Merged PRs (30d)
233

Description

The enhancement may already be reported! Please search for the enhancement before creating one.

### Current Behavior:
Specific to SCA, Dependency-Track already supports outdated version detection. However, at the project level, when one visits the "Audit Vulnerabilities" tab, insights of the components that are vulnerable with the current version, severity, GHSA / NVD insights etc. are available but this diagnosis has limited value without any recommendation to retrofit the component. that is commonly available in most SCA tools and platforms

### Proposed Behavior:
It would be nice to have Dependency Track recommend or provide insights to the "Safer & Closest Version" or "Safest Version" for the vulnerable component version in use. This will help users with an actionable outcome as part of remediating the vulnerability rather than looking at other SCA tools and external sources on what version to upgrade / downgrade to fix the vulnerable library.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.