Skip to content

Trigging Vulnerability Analysis on a specific project #4518

Description

@itmanju

Current Behavior

We are trying to Triger Vulnerability Analysis on a specific project using Ui and Api cal
But the vulnerabilities are same as before.

But if we re upload the same SBOM it removes old vulnerabilities which are not associated with the components

Steps to Reproduce

1.Enabled Enable fuzzy CPE matching. for internal analyser.
2.upload a project
3. you will find lot of vulnerabilties which are not even associated with components present.
4. disabled Enable fuzzy CPE matching. for internal analyser.
5. clicked on reanalyze in audit vulnerabilities section.
6. The vulnerabilities are as before
7. used api call : https://dependencytrack.abilityplatform.abb/api/v1/finding/project/a3e256bd-3dd6-44b3-a7c6-750a34b6c87b/analyze

But still same result

Expected Behavior

Once we disable Enable fuzzy CPE matching. for internal analyser. and click reanalyze it should remove all the unassociated vulnerabilities for components.

Dependency-Track Version

4.12.1

Dependency-Track Distribution

Container Image

Database Server

PostgreSQL

Database Server Version

12.0

Browser

Google Chrome

Checklist

Metadata

Metadata

Assignees

No one assigned

    Labels

    defectSomething isn't workingduplicateThis issue or pull request already exists

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions