DependencyCheck · Issues· 189 open
Open on GitHubLocally synced open issues (discussions stay on GitHub)
- #7608
Include Support for EUVD (European Union Vulnerability Database)
enhancementUpdated Sep 9, 2026 - #8737
Clarification on CVE Reporting Changes in OWASP Dependency-Check
questionmavencentralUpdated Aug 24, 2026 - #8763
OSSIndexAnalyzer cannot parse some CVSS vector strings
ossindexUpdated Aug 22, 2026 - #8757
CENTRAL - NODEAUDIT - POM Cached results never expire
bugUpdated Aug 21, 2026 - #8422
Remove legacy NodeAuditAnalyzer dependency on NPM audit legacy /quick API
npmUpdated Aug 21, 2026 - #8755
Maven: test dependencies sometimes missing when executing with "-T1C"
bugpending more informationmavenUpdated Aug 20, 2026 - #5658
dependency-check report shows in column 'Highest severity' MEDIUM while CVSSv2 has value 8.5 (CVSSv3 has value 6.6)
bugUpdated Aug 9, 2026 - #8469
When the NVD service fails, the retries have no backoff
enhancementnvdUpdated Jun 26, 2026 - #8622
ODC does not shut down connection pools/threads cleanly after some types of failures
bugcoreUpdated Jun 24, 2026 - #7181
Make NvdCveClientBuilder.withThreadCount configurable from CLI
enhancementnvdUpdated Jun 24, 2026 - #8609
Dependency vulnerability scan does not report CVE-2026-40973, but reports newer CVE-2026-4258
enhancementquestionnvdUpdated Jun 13, 2026 - #1827
False Positive due to missing "AND/OR" capabilities defined in the NVD data feed
enhancementpending more informationFP ReportUpdated Jun 10, 2026 - #8571
Yarn Berry analyzer does not report vulnerability score
enhancementnpmUpdated Jun 5, 2026 - #3239
'How to' Documentation missing from File Type Analyzer Descriptions
enhancementdocumentationUpdated Jun 1, 2026 - #1693
Document multi-module configuration with suppression file
documentationmavenUpdated May 31, 2026