DependencyTrack / DependencyTrack/dependency-track

Notify when a vulnerability changes

Open
#2,361 8 comments 8 reactions 0 assignees View on GitHub
enhancement
Dominant language
Java
Stars
4.2k
Forks
811
Avg merge
8h 39m
Merged PRs (30d)
237

Description

### Current Behavior

If a vulnerability changes after it has been created (such as having its severity changed from `Unassigned` to `Critical`), it currently doesn't trigger a notification

### Proposed Behavior

Create a new notification group called `VULNERABILITY_CHANGED`.

Such a notification should be sent when a vulnerability is changed after it has been created, at least for changes that can trigger a change in the risk score (severity, CPE, ...), and list not only that something has changed, but also what changed.

If it is decided to also send notifications for changes in the vulnerability that don't impact the risk score (eg its description), users should be able to opt out of this subset of notifications (eg, having 2 groups : `VULNERABILITY_CHANGED` and `VULNERABILITY_RISK_CHANGED`).

### Checklist

- [X] I have read and understand the [contributing guidelines](https://github.com/DependencyTrack/dependency-track/blob/master/CONTRIBUTING.md#filing-issues)
- [X] I have checked the [existing issues](https://github.com/DependencyTrack/dependency-track/issues) for whether this enhancement was already requested

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.