DependencyTrack / DependencyTrack/dependency-track

operational risk not identified

Open
#2,254 5 comments 0 reactions 0 assignees View on GitHub
defect in triage pending more information
Dominant language
Java
Stars
4.2k
Forks
811
Avg merge
8h 39m
Merged PRs (30d)
237

Description

### Current Behavior

DT is not recognizing operational risks for certain components such as Openssl
![Screenshot 2022-12-08 130703](https://user-images.githubusercontent.com/110160563/206387073-6c12d227-1c6c-44d3-b840-be80899a75a2.jpg)

### Steps to Reproduce

1.By importing the SBOM to DT
[245c6435-8ebb-42b9-a7fb-4635673ee51d-withVulnerabilities.cdx.zip](https://github.com/DependencyTrack/dependency-track/files/10183167/245c6435-8ebb-42b9-a7fb-4635673ee51d-withVulnerabilities.cdx.zip)

### Expected Behavior

Ideally it should show the operational risk for Openssl component by comparing the version

### Dependency-Track Version

4.6.2

### Dependency-Track Distribution

Container Image

### Database Server

PostgreSQL

### Database Server Version

10.1

### Browser

Google Chrome

### Checklist

- [X] I have read and understand the [contributing guidelines](https://github.com/DependencyTrack/dependency-track/blob/master/CONTRIBUTING.md#filing-issues)
- [X] I have checked the [existing issues](https://github.com/DependencyTrack/dependency-track/issues) for whether this defect was already reported

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.