Chapter 4. Known issues


Resolved known issues for this release of Red Hat Trusted Profile Analyzer (RHTPA):

A list of known issues found in this release:

Value inconsistencies between the SBOM bar chart and the pie chart

The Software Bill of Materials (SBOM) documents listed on the bar chart have different values than the pie chart on the RHTPA home page. There is currently no workaround for this issue, and will be fixed in a later release.

The spog-ui-pod-service pod restarts when launching the Trusted Profile Analyzer console in a web browser

When running Red Hat Trusted Profile Analyzer (RHTPA) on Red Hat Enterprise Linux (RHEL), the spog-ui-pod-service pod restarts when first launching Trusted Profile Analyzer console in a web browser causing the application to be unresponsive. To workaround this issue, you can try refreshing the web page or closing the browser tab and reopening the RHTPA console in a new tab. Doing this loads the RHTPA console successfully.

The collector-osv gives a GraphQL error

When the collector-osv sends data to the Graph for Understanding Artifact Composition (GUAC) API without complying to the GraphQL GUAC schema, the default values are not applied for some optional fields, for example, a namespace for a package. GUAC returns the following error message: pq: insert or update on table package_versions violates foreign key constraint package_versions_package_names_versions. This causes the ingestion of OpenSource Vulnerability (OSV) data to fail, and as a consequence some packages could have fewer vulnerabilities reported than expected. Currently there is no workaround for this issue.

Inconsistencies between the total number of CVEs displayed on the dashboard and the CVE tab

The total number of Common Vulnerabilities and Exposures (CVE) uses different filters between the RHTPA home page dashboard and the CVE tab on the search results page, causing the discrepancy between the two values. Currently, there is no workaround for this known issue.

Data migration fails when upgrading from Trusted Profile Analyzer 1.1.2 to 1.2

The bombastic and vexation collector pods crash when there is no space left on the persistent volume claim (PVC) for the PostgreSQL instance. To workaround this potential issue, increase the size of the PVC by 10 GB.

An API error on the package details page

In the RHTPA console, when navigating from the Vulnerabilities page to the package details page, clicking the affected dependencies link gives you the following error message:

API error: Error contacting GUAC (Guac) - Client error: Cannot find an SBOM for PackageUrl

Currently, there is no workaround for this known issue.

Package version mismatch between the API response and the HTML report for Red Hat Dependency Analytics

Opening a manifest file for analysis in Visual Studio Code or IntelliJ, can give you a different package version number between the Red Hat Dependency Analytics (RHDA) HTML report and an API client response. Before analyzing the manifest file, the API client compares package versions in the manifest file to the installed package versions within the client’s environment. When there is a difference in package version, you receive an error message containing the first package version mismatch. To workaround this issue, you can disable the Match Manifest Versions option of RHDA extension in your integrated development environment (IDE).

Back to top
Red Hat logoGithubredditYoutubeTwitter

Learn

Try, buy, & sell

Communities

About Red Hat Documentation

We help Red Hat users innovate and achieve their goals with our products and services with content they can trust. Explore our recent updates.

Making open source more inclusive

Red Hat is committed to replacing problematic language in our code, documentation, and web properties. For more details, see the Red Hat Blog.

About Red Hat

We deliver hardened solutions that make it easier for enterprises to work across platforms and environments, from the core datacenter to the network edge.

Theme

© 2025 Red Hat