DependencyTrack / DependencyTrack/dependency-track

Inherited Risk & Other Metrics: Totalling for Different Views

Open
#451 0 comments 1 reaction 0 assignees View on GitHub
enhancement p2
Dominant language
Java
Stars
4.2k
Forks
811
Avg merge
8h 39m
Merged PRs (30d)
237

Description

### Current Behavior:
Currently, "Inherited Risk Score" is displayed per project, and for the Portfolio as a whole.
"Projects at Risk" count (etc) is displayed only for the Portfolio.

### Proposed Behavior:
Display metrics for different criteria
* **Team** (coming in v3,9 per #140). It would be a security issue (information leakage) if metrics for the whole Portfolio were displayed to a team that only has access to a subset of projects... and would give reduced functionality for the team (as they do not know the metrics for their own subset of projects).
* **Tag**. See #238.
* **Active/Inactive** (released in v3.6). Using Inherited Risk as an example. if Portfolio Risk is 10,000 and 9,500 comes from Inactive Projects, then being able to filter metrics for "Active" makes a huge difference!
* **Scope** See #449 eg, metrics excluding test components
* **Type**

Contributor guide

Open the contributing guide

Research direction

Review the current Portfolio and project metric views, then read related issues #140, #238, and #449 to understand the planned Team, Tag, and Scope criteria. Clarify how Active/Inactive and Type filters should combine with access restrictions; done should include correctly totaled metrics for each supported view without leaking inaccessible projects.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
analytics, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.