Group-level dependency list shows duplicate entries with empty vulnerability details when expanded.
Summary
Group-level dependency list shows duplicate entries with a vulnerability badge, but an empty vulnerability list when expanded.
- Related issues #568028 (closed) and #568063
- Customer reported via ZD 649656
Steps to reproduce
- Complete the scenario from the previous related issue #568063.
- Navigate to the parent group level
- Go to Secure > Dependency list
- Search for the target vulnerable component
- Observe duplicate entries for the same component
- Click to expand the entry that shows "yellow 1 vulnerability detected label"
- One of the duplicates is missing a vulnerability.
Example Group:
What is the current bug behavior?
- The group-level dependency list displays duplicate entries for the same component.
- One duplicate shows a yellow badge indicating "1 vulnerability detected", but when expanded, the vulnerability list is empty.
What is the expected correct behavior?
The group-level dependency list should:
- Show a single entry per component with all vulnerabilities consolidated,
- Show accurate vulnerability counts and details when expanded for each duplicate entry
Relevant screenshots
Output of checks
Patch release information for backports
No security or high impact bug.
Edited by 🤖 GitLab Bot 🤖