dependency-track icon indicating copy to clipboard operation
dependency-track copied to clipboard

Add analysis in Vulnerabilities-> Affected Projects Report

Open jenspopp opened this issue 2 months ago • 0 comments

Current Behavior

I do a vulnerability Audit for my project, I click on the vulnerability -> Affected Projects to see, if other projects are affected. I see: Name, version, active as columns

Proposed Behavior

It would improve usability if there would be an additional column: Analysis. That would enable me to see immediately if another project already analyzed the issue. Right now I need to click through all projects to find that answer. So basically combining:

/v1/vulnerability/source/:source/vuln/:vuln --> vulnerabilityUuid, affecedComponentUuid (s)

and

/v1/analysis?component={affectedComponentUuids}&vulnerability={vulnerabilityUuid}

to get at least analysisState as additional column.

Advanced: It would also be good, to have a report of all analyses, that were made for one vulnerability. That way I could review all analyses and select an existing one (copy analysisState, analysisJustification, analysisResponse, analysisDetails with new audit trail. ) if it matches.

Checklist

jenspopp avatar Nov 26 '25 12:11 jenspopp