Skip to content

Same vulnerability is reported several times #2151

@lsoumille

Description

@lsoumille

Current Behavior

In our DependencyTrack instance for some components, we have duplicates vulnerability reports. See associated screenshots.

image

After digging in DependencyTrack databases we can several entries in the table COMPONENTS_VULNERABILITIES but we don't understand how that's possible.

This is issue as we are using these thresholds in build gates.

Steps to Reproduce

  1. We were not able to reproduce it for distinct components, it seems to appear in a non deterministic way.

Expected Behavior

I want to have only one entry per vulnerability in DependencyTrack report

Dependency-Track Version

4.5.x

Dependency-Track Distribution

Container Image

Database Server

PostgreSQL

Database Server Version

10.18

Browser

N/A

Checklist

Metadata

Metadata

Assignees

No one assigned

    Labels

    defectSomething isn't workingp2Non-critical bugs, and features that help organizations to identify and reduce risksize/MMedium effort

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions