Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Last BOM import results from Dependency-Track unclear #10545

Open
denniebouman opened this issue Dec 19, 2024 · 0 comments
Open

Last BOM import results from Dependency-Track unclear #10545

denniebouman opened this issue Dec 19, 2024 · 0 comments
Labels
Feature New, enhanced, or removed feature

Comments

@denniebouman
Copy link
Member

Describe the bug
When using multiple projects in Dependency-Track, with:

Metric type: Source up-to-dateness
Source type: Dependency Track
Project event type(s): last BOM import

Then all projects are displayed in the Dependency-Track tab, regardless whether they meet the metric target or not.
The metric may indicate (with the correct metric target) which project has the oldest BOM import, based on the number of days.

The above causes confusion, because other metrics, most of the time, show the number of violations in the metric and only the findings in the detail tab.

Possible adjustment(s)

  • Make metrics configurable for:
    • Metric scale: Count and Metric unit: days
    • Metric scale: Count and Metric unit: number of violations
  • Keep the implementation as-is and in the detail tab provide the violations with a color with the deviations from the metric target
  • Keep implementation as-is and use a toggle to show only violations in the detail tab, or all projects
  • ..
@denniebouman denniebouman added the Bug Something isn't working label Dec 19, 2024
@fniessink fniessink added Feature New, enhanced, or removed feature and removed Bug Something isn't working labels Dec 20, 2024
@fniessink fniessink moved this from Inbox to To be refined in Quality-time backlog Dec 20, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Feature New, enhanced, or removed feature
Projects
Status: To be refined
Development

No branches or pull requests

2 participants