DependencyTrack / DependencyTrack/dependency-track

Vulnerability Audit Grouped View: Affected Projects count includes surpressed vulnerabilities

Open
#4,507 1 comment 0 reactions 0 assignees View on GitHub
defect in triage
Dominant language
Java
Stars
4.2k
Forks
811
Avg merge
8h 39m
Merged PRs (30d)
237

Description

### Current Behavior

For some vulnerabilities it shows affectedProjects == 1 in Vulnerability Audit Grouped view.
But in reality the affected project count is zero. When clikcing on the VulnID and going to the Vulnerability page it shows affectedProjects==0, which is correct.

![Image](https://github.com/user-attachments/assets/c05b4feb-7c0d-4f79-9e3e-68e1614d61e2)

![Image](https://github.com/user-attachments/assets/cb17c3f3-50ce-4cc9-9202-9d37eb55931c)

### Steps to Reproduce

Look for vulnerability that affects at least 2 projects.
Observe in Vulnerability Audit View Grouped it shows 2 affected projects.
Surpress the vulnerability for 1 project
Observe in Vulnerability Audit View Grouped it still shows 2 affected projects.
Observe that on the Vulnerability details page it shows 1 affected projects.

### Expected Behavior

Affected projects should only count non-surpressed vulnerabilities?

Alternatively add a filter option to let the user decide.

### Dependency-Track Version

4.12.2

### Dependency-Track Distribution

Container Image

### Database Server

PostgreSQL

### Database Server Version

_No response_

### Browser

Google Chrome

### Checklist

- [x] I have read and understand the [contributing guidelines](https://github.com/DependencyTrack/dependency-track/blob/master/CONTRIBUTING.md#filing-issues)
- [x] I have checked the [existing issues](https://github.com/DependencyTrack/dependency-track/issues) for whether this defect was already reported

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.