DependencyTrack / DependencyTrack/dependency-track
Inconsistancy of vulnerability found on day to day basis and lack of update on vulnerability analysis.
- Dominant language
- Java
- Stars
- 4.2k
- Forks
- 811
- Avg merge
- 8h 39m
- Merged PRs (30d)
- 237
Description
### Current Behavior
When uploading the same SBOM (attached as a zip file),
I expect the same vulnerability to be found (or at least updated).
Right now the result vary from day to day and I was under the impression that ODT has task that run periodically to identify any new vulnerabilities.

just the vulnerability id:
CVE-2022-38752
CVE-2023-1370
CVE-2023-20862
CVE-2023-20863
CVE-2023-20873
CVE-2023-20883
sonatype-2020-0907
sonatype-2021-1074
sonatype-2022-1764
sonatype-2022-6438
[odt_annuaire_inconsistance.xlsx](https://github.com/DependencyTrack/dependency-track/files/11593576/odt_annuaire_inconsistance.xlsx)
[annuaire-service-bom.zip](https://github.com/DependencyTrack/dependency-track/files/11593617/annuaire-service-bom.zip)
Running 4.7.1.
### Steps to Reproduce
1. With ODT 4.7.1, upload the same SBOM every day.
2. Watch for score discrepancy.
### Expected Behavior
Having the same vulnerabiliteis without having to trigger manuel scan or re-uploading the SBOM.
### Dependency-Track Version
4.7.x
### Dependency-Track Distribution
Container Image
### Database Server
Microsoft SQL Server
### Database Server Version
_No response_
### Browser
N/A
### Checklist
- [X] I have read and understand the [contributing guidelines](https://github.com/DependencyTrack/dependency-track/blob/master/CONTRIBUTING.md#filing-issues)
- [X] I have checked the [existing issues](https://github.com/DependencyTrack/dependency-track/issues) for whether this defect was already reported
Contributor guide
Assessment
This issue has not been assessed yet.