DependencyTrack / DependencyTrack/dependency-track

Please create a method to detect automatically deprecated CPE's

Open
#2,390 0 comments 0 reactions 0 assignees View on GitHub
enhancement
Dominant language
Java
Stars
4.2k
Forks
811
Avg merge
8h 39m
Merged PRs (30d)
237

Description

### Current Behavior

Currently Dependencytrack does not check if a CPE has been deprecated. This means that a component does not flag any new vulnerability.

### Proposed Behavior

Whenever a CPE gets deprecated, please flag this so the component CPE can be updated... As an example I have attached the recent CPE deprecation of Windows OS CPE.... This was also the reason why this was detected (since the January fixes didn't show up).

![CPE-Deprecated](https://user-images.githubusercontent.com/35631189/213148068-89181985-5f15-4af3-a9ba-dc97ed4944db.JPG)

### Checklist

- [X] I have read and understand the [contributing guidelines](https://github.com/DependencyTrack/dependency-track/blob/master/CONTRIBUTING.md#filing-issues)
- [X] I have checked the [existing issues](https://github.com/DependencyTrack/dependency-track/issues) for whether this enhancement was already requested

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.