DependencyTrack / DependencyTrack/dependency-track
Dependency that has 1 vulnerability detected in one project and no vulnerability in another.
- Dominant language
- Java
- Stars
- 4.2k
- Forks
- 811
- Avg merge
- 8h 39m
- Merged PRs (30d)
- 237
Description
### Current Behavior
Hello, we are using Dependency Track 4.5.0, and we are facing an odd behavior.
In one project, we find that the dependency lucenequeryparser 4.7.2 contains 1 vulnerability.
and in another project, the same dependency ( with same version) / having the same purl .. doesn't show any vulnerability.
We tried to reupload new boms, rescan the Boms.. but nothing has changed.
Can you please tell what is happening on our side and how we can fix it ?
Thank you in advance.
Best Regards,
### Steps to Reproduce
1.using lucenequeryparser 4.7.2 as a dependency
### Expected Behavior
having the same number of vulnerabilities for the same exact component.
### Dependency-Track Version
4.7.x
### Dependency-Track Distribution
Executable WAR
### Database Server
PostgreSQL
### Database Server Version
_No response_
### Browser
Google Chrome
### Checklist
- [X] I have read and understand the [contributing guidelines](https://github.com/DependencyTrack/dependency-track/blob/master/CONTRIBUTING.md#filing-issues)
- [X] I have checked the [existing issues](https://github.com/DependencyTrack/dependency-track/issues) for whether this defect was already reported
Contributor guide
Assessment
This issue has not been assessed yet.