DependencyTrack / DependencyTrack/dependency-track

Same component has vulnerabilites in one project, but not in another

Open
#4,996 4 comments 1 reaction 0 assignees View on GitHub
defect p2 size/L
Dominant language
Java
Stars
4.2k
Forks
811
Avg merge
8h 39m
Merged PRs (30d)
237

Description

### Current Behavior

One of my users reported that one of his dependencies is showing as having vulnerabilities in one of his projects. He does however use this dependency in multiple projects and in others it is not shown as having vulnerabilities.
According to OSSIndex, the dependency should NOT have any vulnerabilities!

### Steps to Reproduce

Not sure if this is reproducible, we've just been uploading SBOMs for projects and during the audit noticed this issue.

### Expected Behavior

I expect a component that is used multiple times to have the same (or no) vulnerabilities between all projects.

### Dependency-Track Version

4.13.2

### Dependency-Track Distribution

Container Image

### Database Server

PostgreSQL

### Database Server Version

16.8

### Browser

Mozilla Firefox

### Checklist

- [x] I have read and understand the [contributing guidelines](https://github.com/DependencyTrack/dependency-track/blob/master/CONTRIBUTING.md#filing-issues)
- [x] I have checked the [existing issues](https://github.com/DependencyTrack/dependency-track/issues) for whether this defect was already reported

![Image](https://github.com/user-attachments/assets/2453b05b-4162-4f11-bb8f-5a0055d91c6b)

![Image](https://github.com/user-attachments/assets/9830eb4a-a2af-4c9d-a40c-f6fd6b1cc4c1)

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.