Skip to content

Defined artefact version in the hints file is ignored #5812

@bondarei

Description

@bondarei

Describe the bug
A defined version 3.4.11 for the avcodec-vsdk-57.dll in the hints file doesn't appear in the report as part of a cpe. The report contains only
[cpe:2.3:a:ffmpeg:ffmpeg:57:::::::*] (Confidence:Highest)
cpe:2.3:a:ffmpeg-sdk_project:ffmpeg-sdk:57:::::::*

Version of dependency-check used
The problem occurs using dependency-check version: 8.0.1 of the cli.

To Reproduce
Steps to reproduce the behavior:
Execute scan with cli tool of the attached assembly with the attached hints file and verify the report.

Expected behavior
expected something like this:
cpe:2.3:a:ffmpeg:ffmpeg:3.4.11:::::::*
cpe:2.3:a:ffmpeg:ffmpeg:57:::::::*

Additional context
hints.zip
avcodec-vsdk-57.zip

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions