Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feature: Adding proper logging to warn users when VEX data is not taken into account #2989

Conversation

syalioune
Copy link
Contributor

@syalioune syalioune commented Aug 27, 2023

Description

Adding proper logging to warn users when VEX data is not taken into account because either :

  • Vulnerability source/id on VEX does not match the one in DT database
  • Vulnerability source on VEX is missing

Addressed Issue

Fix #2977

Additional Details

N/A

Checklist

  • I have read and understand the contributing guidelines
  • [] This PR fixes a defect, and I have provided tests to verify that the fix is effective
  • [] This PR implements an enhancement, and I have provided tests to verify that it works as intended
  • [] This PR introduces changes to the database model, and I have added corresponding update logic
  • [] This PR introduces new or alters existing behavior, and I have updated the documentation accordingly

Copy link
Member

@nscuro nscuro left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @syalioune! 😎

@nscuro nscuro added the enhancement New feature or request label Aug 27, 2023
@nscuro nscuro added this to the 4.9 milestone Aug 27, 2023
@nscuro nscuro merged commit 9c830ef into DependencyTrack:master Aug 27, 2023
7 checks passed
@github-actions github-actions bot locked as resolved and limited conversation to collaborators Sep 27, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
enhancement New feature or request
Projects
None yet
Development

Successfully merging this pull request may close these issues.

VEX does not apply when source is empty or unequal source from analysis
2 participants