CVEs showing duplicates #1209
Replies: 1 comment 1 reply
-
For Seeing a The examples you give above prove that Dependency-Track will display duplicates. But it does not specifically call them out... which can be a pain in a project with hundreds of components. Thus, I use cyclonedx-cli tool. Using a real example to illustrate:
Note that the reporting of the presence of multiple versions here proves that what you are seeing is in the BOM itself and that Dependency-Track has reported things correctly. Although the clash might be resolved by a simple addition to dependencyManagement you might also want to know WHERE the clash came from.
|
Beta Was this translation helpful? Give feedback.
-
Hi @stevespringett ,
After a project is build and published in Dependency Track, we could see duplicate CVEs reported on the application as well components are duplicated which makes the vulnerabilities number increased. Is this the normal behavior of Dependency track tool ?
Regards,
Aejaz
Beta Was this translation helpful? Give feedback.
All reactions