dependency-track icon indicating copy to clipboard operation
dependency-track copied to clipboard

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.

Results 588 dependency-track issues
Sort by recently updated
recently updated
newest added

When importing a BOM containing only services (such as a SaaSBOM), DT throws a NPE. Currently, DT assumes a BOM will always have components, thus resulting in an NPE.

defect
pending release

### Current Behavior: Dependency track is giving 2 different severity results for the same vulnérability. ![image](https://user-images.githubusercontent.com/43956285/177761972-8930fe49-0dd6-4713-86b4-23bb4bf19908.png) ![image](https://user-images.githubusercontent.com/43956285/177762133-84670165-1171-4e84-b364-6e862a999235.png) the first one is on H2, the second is on PostgreSQL. i have...

cannot reproduce
in triage

The defect may already be reported! Please search for the defect before creating one. ### Current Behavior: amqp-client use three licenses: MPL2.0 Apache 2.0 GPL2.0 https://github.com/rabbitmq/rabbitmq-java-client/blob/main/LICENSE ![image](https://user-images.githubusercontent.com/17465789/149861015-941f71cd-f825-4765-b89d-e6b5bb42bf9a.png) ### Steps to...

enhancement

The defect may already be reported! Please search for the defect before creating one. ### Current Behavior: Jenkins Dependecy tarck jobs fails since server takes more 30 minutes analyze the...

defect

### Current Behavior: Currently, each vulnerability is unique by its source and identifier. However, different sources have different identifiers for the same vulnerability. This leads to duplicate vulnerabilities, increased risk...

enhancement

### Current Behavior: I am responsible for security questions in all of our projects, including tooling like Dependency-Track and PSIRT process. Even though projects should typically handle things on their...

enhancement

### Current Behavior: If a new project is created from an uploaded BOM, the number of components is correct. But if the same file is re-uploaded (regardless via UI or...

cannot reproduce
pending more information
in triage

### Current Behavior: When trying to add an ldap (active directory) user with a DN of more than 255 characters long, the user is added but in the interface in...

enhancement

### Current Behavior: When starting a fresh instance of Dependency-Track, there are no projects in the portfolio. ### Proposed Behavior: Add Dependency-Track as default project to every new portfolio, with...

enhancement
p2

Ticket #140 describes the initial support for Portfolio ACLs (beta) and covers the majority of cases. However, there are known gaps and these gaps will be implemented in this ticket....

enhancement
access control
needs milestone