Skip to content

TPL is not reported as vulnerable #8140

@shriharikalessnc

Description

@shriharikalessnc

Precondition

  • [Scan package should contain Azure.Identity.dll with file version 1.700.22.46903 and product version 1.7] I checked the issues list for existing open or closed reports of the same problem.

Describe the bug
Azure.Identity.dll@1.7.0 is not reported as vulnerable and package name is taken as pkg:generic/Azure.Identity@1.700.22.46903. Ideally it should report it as vulnerable.

Version of dependency-check used
The problem occurs using version 12.1.9 of the cli (cli, gradle plugin, maven plugin, etc.)

Expected behavior
Azure.Identity.dll@1.7.0 should report as vulnerable

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions