DependencyTrack / DependencyTrack/dependency-track

Internal Library with same name issue

Open
#4,487 1 comment 0 reactions 0 assignees View on GitHub
defect in triage
Dominant language
Java
Stars
4.2k
Forks
811
Avg merge
8h 39m
Merged PRs (30d)
237

Description

Hi, I have an internal library with names like common, transformers, … that after scanning with cyclone-dx and uploading the result to the dependency tracker detects vulnerable and seems DT confusing with a library with a similar name.
E.g. Detect transformers as huggingface transform, while my library is something else.

My library has a group/version that distinguishes it from another library so why does it detect it incorrectly?
I don't want to rename my library is there any other solution?

FYI: try to add in administrator > internal library but not work as expected and still detected it!

Any idea?
Thanks

DT version 4.12.2

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.