Skip to content

Fuzzy Matching as project setting instead of global #5577

@BrightKn1ght

Description

@BrightKn1ght

Current Behavior

Currently fuzzy matching setting is a global setting which affects all projects. We have a Dependency Track instance running in your company and different departments are using it. Some are now wanting to scan with Fuzzy Matching while the others are complaining about too many False Positives.

Proposed Behavior

I would suggest the following:

  1. Adding a toggle button to the project creation dialog allowing to enable/disable the fuzzying on per project level.
  2. Marking the vulnerabilities found by fuzzying with a flag, which allows filtering them later in the UI. Probably the code section where to flag them could be here and here

Checklist

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions