DependencyTrack / DependencyTrack/dependency-track

Inconsistancy of vulnerability found on day to day basis and lack of update on vulnerability analysis.

Open
#2,792 5 comments 0 reactions 0 assignees View on GitHub
defect in triage
Dominant language
Java
Stars
4.2k
Forks
811
Avg merge
8h 39m
Merged PRs (30d)
237

Description

### Current Behavior

When uploading the same SBOM (attached as a zip file),
I expect the same vulnerability to be found (or at least updated).
Right now the result vary from day to day and I was under the impression that ODT has task that run periodically to identify any new vulnerabilities.

![image](https://github.com/DependencyTrack/dependency-track/assets/1593248/7dd39ccc-6b55-4462-9513-bd7a1c4d607d)

just the vulnerability id:
CVE-2022-38752
CVE-2023-1370
CVE-2023-20862
CVE-2023-20863
CVE-2023-20873
CVE-2023-20883
sonatype-2020-0907
sonatype-2021-1074
sonatype-2022-1764
sonatype-2022-6438

[odt_annuaire_inconsistance.xlsx](https://github.com/DependencyTrack/dependency-track/files/11593576/odt_annuaire_inconsistance.xlsx)
[annuaire-service-bom.zip](https://github.com/DependencyTrack/dependency-track/files/11593617/annuaire-service-bom.zip)

Running 4.7.1.

### Steps to Reproduce

1. With ODT 4.7.1, upload the same SBOM every day.
2. Watch for score discrepancy.

### Expected Behavior

Having the same vulnerabiliteis without having to trigger manuel scan or re-uploading the SBOM.

### Dependency-Track Version

4.7.x

### Dependency-Track Distribution

Container Image

### Database Server

Microsoft SQL Server

### Database Server Version

_No response_

### Browser

N/A

### Checklist

- [X] I have read and understand the [contributing guidelines](https://github.com/DependencyTrack/dependency-track/blob/master/CONTRIBUTING.md#filing-issues)
- [X] I have checked the [existing issues](https://github.com/DependencyTrack/dependency-track/issues) for whether this defect was already reported

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.