Skip to content

Conversation

@tdruez
Copy link
Contributor

@tdruez tdruez commented Nov 25, 2025

Using "Replace existing relationships by newer version."
If the current Package assigned to the Product is vulnerable, when updating the relationship with a non-vulnerable Package version, the weighted_risk_score of the relationship is not updated.
This result into displaying the Product as vulnerable even if it is not anymore.

@tdruez tdruez merged commit 5101b51 into main Nov 25, 2025
4 of 5 checks passed
@tdruez tdruez deleted the weighted-risk-score branch November 25, 2025 10:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant