Researching and Identifying Fixes
SCA, SBOM, and Container scans will all have a package references section showing the source file (such as a manifest), and the package or packages where the issue was detected.
The package reference shown is the actual package introducing the issue, and may not be the direct dependency.
To view the direct dependency (and the full introduction path(s)) click the package to view it in the Dependency Tree.
When viewing the issues, Vulnerability Issues, Dependency Typo Issues, and Dependency Substitution Issues may have available fixes and will display a 'fix' icon (a green wrench and screwdriver). Vulnerabilities which are identified as 'exploitable' will be shown with an exploitability icon (a red shield with an explanation mark).
data:image/s3,"s3://crabby-images/3bd9a/3bd9a1df83c7812aaf7908bf44cb12e55e9a785a" alt="Issues with fixes and/or exploitable Issues with fixes and/or exploitable"
SOOS detects fixes by following the version syntax rules for the selected package manager. Following these rules, SOOS will locate any newer package versions which are free of vulnerabilities and satisfy the version syntax for all packages in the introduction path (this means the versions shown will not only fix the vulnerability that was found, but also will not introduce some other vulnerability and follow SemVer versioning rules).
For package managers like NPM, where translative dependencies cannot be directly updated SOOS will calculate a new sub-dependency tree that is free of any vulnerabilities (for any package in the tree), all the way up to the direct dependency.
SOOS will also calculate these new sub-trees for any introduction path for the transitive dependency, which often means upgrading multiple direct dependency packages.
If available updates are found, they will show in the Fix section. See Creating Tickets & Pull Requests for more information on applying fixes.
data:image/s3,"s3://crabby-images/4ef12/4ef12aa4a6e44994687889aec12b4373464b2241" alt="Fix (newer versions) are available Fix (newer versions) are available"
Because of the complexity in calculating new sub-trees and following SemVer rules, there are cases when a direct dependency cannot be upgraded to fix a transitive dependency issue. Even for some direct dependencies with issues (or package managers that support transitive dependency updates), there may not be a newer version available to upgrade to. In these cases SOOS will display a message indicating the inability to find a suitable upgrade.
In these cases a ticket may still be created, but it will not have upgrade details. Alternatively, use the Issue Suppression and Attestation workflows to temporarily, or permanently, suppress the issue.
For NPM specifically, when no transitive upgrade path is found, SOOS will indicate that a package override may fix the issue, but will warn that doing so may introduce compatibility issues.
data:image/s3,"s3://crabby-images/74116/74116ce5113962f144f94fde086c28eeb56274c9" alt="Document image Document image"