DependencyTrack / DependencyTrack/dependency-track
Inherited Risk & Other Metrics: Totalling for Different Views
- Dominant language
- Java
- Stars
- 4.2k
- Forks
- 811
- Avg merge
- 8h 39m
- Merged PRs (30d)
- 237
Description
### Current Behavior:
Currently, "Inherited Risk Score" is displayed per project, and for the Portfolio as a whole.
"Projects at Risk" count (etc) is displayed only for the Portfolio.
### Proposed Behavior:
Display metrics for different criteria
* **Team** (coming in v3,9 per #140). It would be a security issue (information leakage) if metrics for the whole Portfolio were displayed to a team that only has access to a subset of projects... and would give reduced functionality for the team (as they do not know the metrics for their own subset of projects).
* **Tag**. See #238.
* **Active/Inactive** (released in v3.6). Using Inherited Risk as an example. if Portfolio Risk is 10,000 and 9,500 comes from Inactive Projects, then being able to filter metrics for "Active" makes a huge difference!
* **Scope** See #449 eg, metrics excluding test components
* **Type**
Contributor guide
Research direction
Review the current Portfolio and project metric views, then read related issues #140, #238, and #449 to understand the planned Team, Tag, and Scope criteria. Clarify how Active/Inactive and Type filters should combine with access restrictions; done should include correctly totaled metrics for each supported view without leaking inaccessible projects.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- analytics, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100