DependencyTrack / DependencyTrack/dependency-track

GHSA-v5pm-xwqc-g5wc not matching Microsoft.OpenAPI@2.0.0

Open
#6,565 8 comments 0 reactions 0 assignees View on GitHub
defect pending more information
Dominant language
Java
Stars
4.2k
Forks
811
Avg merge
8h 39m
Merged PRs (30d)
237

Description

### Current Behavior

GHSA-v5pm-xwqc-g5wc not matching Microsoft.OpenAPI@2.0.0

### Steps to Reproduce

1. Add PackageReference onto Microsoft.OpenAPI@2.0.0
2. Export SBOM to DependencyTrack
3. Ensure GHSA-v5pm-xwqc-g5wc is known in DependencyTrack
4. Ensure Internal Analyzer is enabled
5. Observe it's not matched
### Expected Behavior

GHSA-v5pm-xwqc-g5wc MUST match Microsoft.OpenAPI@2.0.0

DependencyTrack GHSA information:
Image

Imported SBOM information:
Image

### Dependency-Track Version

4.x

### Browser

Microsoft Edge

### Checklist

- [x] I have read and understand the [contributing guidelines](https://github.com/DependencyTrack/dependency-track/blob/main/CONTRIBUTING.md#filing-issues)
- [x] I have checked the [existing issues](https://github.com/DependencyTrack/dependency-track/issues) for whether this defect was already reported

Contributor guide

Open the contributing guide

Research direction

Start by tracing the Internal Analyzer's matching path for the GHSA-v5pm-xwqc-g5wc advisory and the Microsoft.OpenAPI@2.0.0 component. Reproduce the case with the listed PackageReference, SBOM export, Dependency-Track advisory, and enabled Internal Analyzer; done means the advisory matches that component without breaking related matching.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.