DependencyTrack / DependencyTrack/dependency-track

Tracking Timestamps for Components and Dependencies

Open
#293 3 comments 0 reactions 1 assignee Claimed by @stevespringett View on GitHub
enhancement p2
Dominant language
Java
Stars
4.2k
Forks
811
Avg merge
9h 4m
Merged PRs (30d)
229

Description

### Issue Type:
- [ ] defect report
- [X] enhancement request

### Current Behavior:
I believe that it would be useful to track timestamps for "first seen" info for both components and dependencies. The timestamps should be displayed in the UI in sortable columns (and perhaps not displayed by default).

Examples:
For dependencies, (Project tab -> Dependencies), seeing which dependencies are new would let one quickly see that there are (or are not) associated vulnerabilities. Or help one identify which components are the likely cause of an increase in "Total components"

For components, it would be useful to know when each unique component was first uploaded tio Dependency-Track:
* Component tab: eg, filter by (say) "jackson-databind" and see just one instance with vulnerabilities that is brand new, emphasising the need for closer inspection
* Project Tab -> Dependencies. Use in conjunction with the dependency timestamp to see that (say) a threat relates to a component that is brand new to both DT itself and to the project. Or that the vulnerable component is brand new to the project as a dependency but has been known to DT "for ages" (something that would make me question why a vulnerability is being introduced that we already know about from other projects).

### Environment:

- Dependency-Track Version: 3.4.0

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.