DependencyTrack / DependencyTrack/dependency-track
Vulnerable Component Ratio Missing Data
- Dominant language
- Java
- Stars
- 4.2k
- Forks
- 811
- Avg merge
- 8h 39m
- Merged PRs (30d)
- 237
Description
The "Vulnerable Component Ratio" often fails to display the 2nd integer (denominator?).
### Current Behavior:
The "Vulnerable Component Ratio" displays on the top-right of the dashboard. The 2nd integer in the ratio seems to appear and disappear. In other words, I have seen it fail to display for a while and then (I am pretty sure) it did display. And currently it is not...

If a ratio is defined as A:B, we have A, but not B.
### Steps to Reproduce:
Navigate to dashboard and inspect. I am not sure how to reproduce (ie, cause "B" to poof).
### Expected Behavior:
* Vulnerable Component Ratio should display correctly
* (Desired) A bit of documentation. The word "ratio" does not appear on the docs website.
### Environment:
- Dependency-Track Version: 3.5.0
- Distribution: [ Traditional WAR]
- BOM Format & Version: CycloneDX 1.0
- Database Server: [ PostgreSQL ]
- Browser: Firefox v67.0.1 and Chrome 75.0.3770.80.
Contributor guide
Research direction
Start at the dashboard's top-right Vulnerable Component Ratio and inspect when its denominator disappears in the reported 3.5.0 environment. The issue names no source files or tests and provides no reliable trigger, so first establish a reproducible case. Done means the ratio consistently displays both values; the report also requests documentation explaining the metric.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java, postgresql
- Domain
- documentation, frontend
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 43/100