Report Outdated Components (OWASP Top 10: A06:2021) #2559
walterdeboer
started this conversation in
Show and tell
Replies: 1 comment 5 replies
-
I would not expect to find outdated components while in the "Audit Vulnerabilities" tab. Most large software applications with hundreds or thousands of OSS components will use a lot of out-of-date components, most will not be vulnerable. It will be frustrating for users to have to paginate through the noise to find the vulnerabilities. This would be a UX disaster if implemented. This information should either be on a dedicated tab, or not included at all since users can create policy for outdated components which would then trigger a violation. |
Beta Was this translation helpful? Give feedback.
5 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Outdated Components is in the OWASP Top 10: A06:2021 – Vulnerable and Outdated Components
Dependency Track knows of outdated component, but does not show them in the Audit Vulnerabilities overview when there is no known vulnerability
If added two PR's so outdated component with no known vulnerabilities are included in the Audit Vulnerabilities overview :
It uses the folowing PR so only stable versions are reported:
N.B. only direct dependencies are reported as these are the ones you could update yourself
closes #2514, #2500, fixes #513, #1374, partly fixes #2003, #1833
Please share your thoughts! :-)
Beta Was this translation helpful? Give feedback.
All reactions