dependency-check / dependency-check/dependency-check-sonar-plugin

Issue description being changed to different CVE on repeated runs

Open
#682 14 comments 1 reaction 1 assignee Claimed by @Reamer View on GitHub
bug lifecycle/frozen
Dominant language
Java
Stars
694
Forks
146
PR merge metrics
No merged PRs in 30d

Description

**Describe the bug**
After addressing vulnerabilities in a previous analysis' report, some vulnerability issues within SonarQube are having their descriptions updated with the descriptions of other vulnerabilities that are present in the report. In some cases, issues that had been manually marked with a resolution had the resolution removed, making them appear as if they had never been resolved. Comments, tags, and other features that are managed directly by SonarQube remain the same, only the description and severity are changed to that of another issue.

**To Reproduce**
1. Perform an analysis on a project that results in vulnerabilities.
2. Resolve at least one of these vulnerabilities in code.
3. Perform a second analysis.
4. Some issues will have had their descriptions swapped, and/or their resolved status changed.

**Current behavior**
SonarQube vulnerability issue descriptions and severities are being mixed up on subsequent analyses.

**Expected behavior**
Each issue's description and severity should remain the same once the issue has been created.

**Screenshots**
I used comments to track the issues, by commenting the CVE that the issue was for after the first analysis. After the second analysis, it had changed from the one in the comment to the one in the description.
![image](https://user-images.githubusercontent.com/1619315/181090768-368c7262-5c82-40ad-8c9a-7eeaa0aa6192.png)

**Versions (please complete the following information):**

- dependency-check: 6.5.1
- sonarqube: 9.5.0.56709
- dependency-check-sonar-plugin: 3.0.1

**Additional context**
This appears to be similar to #55.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.