Incorrect nuget dependencies are identified #1755
iamrahul127
started this conversation in
General
Replies: 1 comment 2 replies
-
Hi @iamrahul127 👋 Dependency-Track works with data it's being fed with the BOM you upload. This looks like the tool you used to generate the BOM with produced a BOM with different contents than you expected. What generator were you using to produce the BOM? Is it cyclonedx-dotnet per chance? If so, you may want to file a defect over there. |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Analysis of project referring NServiceBus.Newtonsoft.Json v 2.3.0 results in to identifying incorrect dependency. We expect DT to identify Newtonsoft.Json v 13.0.1 but it's identifying 11.0.2 version of instead as given in below screenshot. This results in finding incorrect vulnerability.
Current Behavior:
Expected Behavior:
Should identify following as dependencies instead
Environment:
Beta Was this translation helpful? Give feedback.
All reactions