DependencyTrack / DependencyTrack/dependency-track
Same component has vulnerabilites in one project, but not in another
- Dominant language
- Java
- Stars
- 4.2k
- Forks
- 811
- Avg merge
- 8h 39m
- Merged PRs (30d)
- 237
Description
### Current Behavior
One of my users reported that one of his dependencies is showing as having vulnerabilities in one of his projects. He does however use this dependency in multiple projects and in others it is not shown as having vulnerabilities.
According to OSSIndex, the dependency should NOT have any vulnerabilities!
### Steps to Reproduce
Not sure if this is reproducible, we've just been uploading SBOMs for projects and during the audit noticed this issue.
### Expected Behavior
I expect a component that is used multiple times to have the same (or no) vulnerabilities between all projects.
### Dependency-Track Version
4.13.2
### Dependency-Track Distribution
Container Image
### Database Server
PostgreSQL
### Database Server Version
16.8
### Browser
Mozilla Firefox
### Checklist
- [x] I have read and understand the [contributing guidelines](https://github.com/DependencyTrack/dependency-track/blob/master/CONTRIBUTING.md#filing-issues)
- [x] I have checked the [existing issues](https://github.com/DependencyTrack/dependency-track/issues) for whether this defect was already reported


Contributor guide
Assessment
This issue has not been assessed yet.