DependencyTrack / dependency-track

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.

Home Page:https://dependencytrack.org/

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

False positive with jetty

amergey opened this issue · comments

Current Behavior

Dependency track detect GHSA-58qw-p7qm-5rvh from github analyzer against jetty 9.4.53 while it was fixed in 9.4.52

image

Steps to Reproduce

1.run dependency track on a project with jetty 9.4.53

Expected Behavior

GHSA-58qw-p7qm-5rvh not reported

Dependency-Track Version

4.10.1

Dependency-Track Distribution

Container Image

Database Server

PostgreSQL

Database Server Version

No response

Browser

Google Chrome

Checklist