Skip to content

Initial Import closes findings in other tests #14353

@AndreVirtimo

Description

@AndreVirtimo

The initial import to a new test closes findings in other tests.

I have an engagement with multiple tests based on Dependency Check reports. Deduplication is on engagement scope.

See the slack discussion for more information: https://defectdojocommunity.slack.com/archives/C0A4DBKANDS/p1771564613056809

Steps to reproduce
Steps to reproduce the behavior:

  1. Go to engagement
  2. Click on Tests menu -> Import Scan Results
  3. Select type "Dependency Check Scan" and upload an empty Dependency Check report.
  4. Activate "Close old findings"
  5. Press "Import"
  6. You can now see the notification "No findings were added/updated/closed/reactivated as the report is empty or the findings in Defect Dojo are identical to those in the uploaded report."
  7. In the Import History you can the import with x closed findings (should be all other active findings with the same test Type)
    Expected behavior
    This should not close any finding outside the target test.

Deployment method (select with an X)

  • Docker Compose
  • Kubernetes
  • GoDojo

Additional context (optional)
This also happens when you create the new test via the reimport API.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions