Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Display main dependency originating indirect vulnerable dependency #463

Open
vipulasri opened this issue Dec 28, 2023 · 0 comments
Open
Labels
feature request New feature or request

Comments

@vipulasri
Copy link

Is your feature request related to a problem? Please describe.
Its hard to pinpoint the exact dependency in the project which has indirect vulnerable dependency which makes it harder to fix/update the dependency with the vulnerability.

In the screenshot below, it's challenging to identify the main dependency from which org.xerial:sqlite-jdbc:3.36.0 originates.
Screenshot 2023-12-28 at 3 52 03 PM

Describe the solution you'd like to see
Currently, the system provides information about indirect dependencies that are vulnerable. However, to enhance transparency and facilitate quicker remediation, it would be beneficial to display the main dependency from which the identified indirect vulnerability originates. This additional information will empower users to pinpoint the root cause more efficiently, enabling a swifter resolution of potential security concerns. The proposed enhancement aims to offer a clearer understanding of the dependency tree, ultimately improving the overall security analysis and management process.

@vipulasri vipulasri added the feature request New feature or request label Dec 28, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
feature request New feature or request
Projects
None yet
Development

No branches or pull requests

1 participant