Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Gitlab report format broken after NVD API changes #6165

Closed
weyhmueller opened this issue Nov 28, 2023 · 0 comments
Closed

Gitlab report format broken after NVD API changes #6165

weyhmueller opened this issue Nov 28, 2023 · 0 comments
Labels

Comments

@weyhmueller
Copy link
Contributor

weyhmueller commented Nov 28, 2023

Describe the bug
PR #5920 introduced dependency check reports in Gitlab's own format. However PR #5978 came with a lot of refactoring and didn't respect that in the changes from #5920.

Version of dependency-check used
The problem occurs using version 9.0.0+ of the dependency check core.

Steps to reproduce the behavior:

  1. Create a dependency check report in GITLAB format
  2. View the resulting json file
  3. Scroll down to then metadata of a vulnerability
  4. See error: severity placeholder from the velocity template is not replaced anymore

Expected behavior
A Gitlab report file that contains information about the severity of the detected vulnerabilites.

For a fix see #6166.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants