DependencyTrack / DependencyTrack/frontend

Unable to delete INTERNAL vulnerability or add additional affected components

Open
#984 1 comment 0 reactions 0 assignees View on GitHub
defect in triage
Dominant language
Vue
Stars
171
Forks
250
Avg merge
10h 56m
Merged PRs (30d)
84

Description

### Current Behavior

With an administrator user (all permissions) I get the "Delete" button on an INTERNAL (manually created) vulnerability, but the button is disabled and not clickable. I cannot delete manually created issues.
Also on the "Affected Components" tab I cannot add additional components and no components are displayed although the vulnerability is linked to a component in one of my projects.

![image](https://github.com/user-attachments/assets/0db7b39f-095e-4adf-b655-5869e266d193)
"Delete" button does not activate when hovered

![image](https://github.com/user-attachments/assets/8694fe07-ed93-488f-884a-c3db27b1c00e)
No additional components can be added here

Tested in Chrome and Firefox
Dependency-Track Version is 4.11.7

### Steps to Reproduce

1. Create a new vulnerability and link it to a component (using PURL)
2. Find the vulnerability in the components project (or in the vulnerability list)
3. View Details
4. There is a delete button but it does not work
5. The Affected Components tab is empty and new components cannot be added

### Expected Behavior

INTERNAL vulnerabilities can be deleted.
Affected Components can be added after creating the vulnerability.

### Dependency-Track Frontend Version

4.11.7

### Browser

Google Chrome

### Browser Version

Chrome 128.0.6613.85; Firefox 129.0.2

### Operating System

Windows

### Checklist

- [X] I have read and understand the [contributing guidelines](https://github.com/DependencyTrack/dependency-track/blob/master/CONTRIBUTING.md#filing-issues)
- [X] I have checked the [existing issues](https://github.com/DependencyTrack/frontend/issues) for whether this defect was already reported

Contributor guide

No contributing guide indexed for this repository

Research direction

The issue names no files, tests, or entry points. Start by reproducing the disabled delete action and empty Affected Components tab in Dependency-Track frontend 4.11.7, then trace the relevant vulnerability-detail UI; done means INTERNAL vulnerabilities can be deleted and affected components can be displayed and added.

Written by the indexing model from the issue text.

Assessment

Domain
frontend
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.