dependency-track
dependency-track copied to clipboard
Surpressing vulnerability does not surpress corresponding policy violation
trafficstars
Current Behavior:
When surpressing a vulnerability, a corresponding policy violation is not surpressed and needs to be surpressed manually too.
Steps to Reproduce:
- Create a policy targeting vulnerabilites
- Have a vulnerable component
- Surpress the vulnerability because the project is not affected
- Check the policy violations
Expected Behavior:
Policy violations should be removed for a surpressed vulnerability
Environment:
- Dependency-Track Version: 4.4.2
- Distribution: Docker
- BOM Format & Version: CycloneDX BOM 1.3