Releases: DependencyTrack/dependency-track
4.11.5
For official releases, refer to Dependency Track Docs >> Changelogs for information about improvements and upgrade notes.
If additional details are required, consult the closed issues for this release milestone.
# SHA1
8fd45ea6ae725e8e7dac59ec9d471fcdaeb42c6d dependency-track-apiserver.jar
eba6cbaa6c2da9ffb295da83ed39af68ff4130a8 dependency-track-bundled.jar
# SHA256
c39c15849cbb7dd19833ea689c20aaf92bc9f6965b758961e1d2a01a2b09f86f dependency-track-apiserver.jar
7ebb11573b2a59084ed98fe92d363240c910dc7b5aa7ebeda64bee7d47089d9a dependency-track-bundled.jar
# SHA512
5c885c595687f20da1792393a161e30f23bb3fdfd9deb31c6010be3da86e839a046d2ba854a52f1148ba38fd368c084c911910a90ea384391cf6cad5e52bc1cd dependency-track-apiserver.jar
eb0e56faa86bae2cb7d81b77e95fa6f809eaa55e7ed8a412dcb15cb4491490ae8398812752e460a07d12ca03b08a0951567be60accd48462c73263388dcd21ef dependency-track-bundled.jar
What's Changed
Bug Fixes 🐛
- Backport: Fix
BOM_CONSUMED
andBOM_PROCESSED
notifications being dispatched with wrong scope for BOM processing V2 by @nscuro in #3941 - Backport: Set license name instead of ID when using custom license by @nscuro (original change by @2000rosser) in #3942
Dependency Updates 🤖
- Backport: Bump io.github.jeremylong:open-vulnerability-clients from 6.1.1 to 6.1.2 by @nscuro in #3940
- Backport: Bump debian from
0200978
tof8bbfa0
by @nscuro in #3943 - Bump
oauth2-oidc-sdk
from 10.15 to 11.13 by @nscuro in #3944 - Bump bundled frontend to 4.11.5 by @nscuro in #3945
Other Changes
Full Changelog: 4.11.4...4.11.5
4.11.4
For official releases, refer to Dependency Track Docs >> Changelogs for information about improvements and upgrade notes.
If additional details are required, consult the closed issues for this release milestone.
# SHA1
19531d4f02cccf26478b3a63feba355da8726b3f dependency-track-apiserver.jar
3c4bb658783157ae9c408b8323e25e55c9ab25fd dependency-track-bundled.jar
# SHA256
9a09259ba4c19d02b81a39fb5894df758f19ff1bb43538d4b999b4a5789a9d9b dependency-track-apiserver.jar
73fc867d347da8a8af14f8c6812e13b870037a28d7de83e2837db9c27d840100 dependency-track-bundled.jar
# SHA512
a357be2617e9da6d4eaf19120316927ccddbc1290b9f0179287619864ffe2f6a349c9cab729853469425e273662e64cb49a4ede5498da937817b3cda01997af9 dependency-track-apiserver.jar
13fbf6477f2820b0926ad082063332e9f34de622e64b11cfe0fa4574ba5d2d9f41c06c791740ddb69a34fc71e21b6456f20c36018eb2b52e0664fdc47a41645f dependency-track-bundled.jar
What's Changed
Enhancements 🚀
Bug Fixes 🐛
- Backport: Fix inverted "show inactive" filter in vulnerability audit view by @nscuro (original change by @2000rosser) in #3864
- Backport: Fix BOM validation failing when URL contains encoded
[
and]
characters by @nscuro in #3866 - Backport: Fix external references not being updated via
POST /v1/component
by @nscuro (original change by @sahibamittal) in #3867 - Backport: Prevent XXE injection during CycloneDX validation and parsing by @nscuro in #3871
Dependency Updates 🤖
Other Changes
Full Changelog: 4.11.3...4.11.4
4.11.3
For official releases, refer to Dependency Track Docs >> Changelogs for information about improvements and upgrade notes.
If additional details are required, consult the closed issues for this release milestone.
# SHA1
ff4284ce635f4da916e907af20bb0e9339349ecd dependency-track-apiserver.jar
beea18173e6a52180ac1a8ee721dd7f775eaaf2d dependency-track-bundled.jar
# SHA256
f1e34cc7a0c5e2fe444e934aa221853ac762ee79997bc10fa712ee6ac8f776d8 dependency-track-apiserver.jar
d62557345bb244b5d34e7a56d057e264044524d8df7964df23383a2ace658cbd dependency-track-bundled.jar
# SHA512
230d1e5eb4d883e1f2d3dfba734b6c8e92a55dbb56e263dab53cb127f01f1ca0f6fc36ac65acfb751dfa11c2a63d8f312a71411a329038dff974e772cb4446da dependency-track-apiserver.jar
832fe98ba16b01b7411ff8a292f9e090295936406e521b3c8794868dc5665bc92c9d5db2657e4441be63a558b23b0da291aec4d277c0b0a50f63d2b5e2bdc38e dependency-track-bundled.jar
What's Changed
Bug Fixes 🐛
Full Changelog: 4.11.2...4.11.3
4.11.2
For official releases, refer to Dependency Track Docs >> Changelogs for information about improvements and upgrade notes.
If additional details are required, consult the closed issues for this release milestone.
# SHA1
174956bf3cd2dab16cfd36e7ab1b5d7001b99160 dependency-track-apiserver.jar
af75c903b033418ea6326cbb4e6885afba99ee94 dependency-track-bundled.jar
# SHA256
135cf4361bbbc65f488796bf196c8d2d3cbebec931b249e037551c6fbbae2ed7 dependency-track-apiserver.jar
5020ac51158038439b7482d5c5fec151773162724dce1779249bf73053456d34 dependency-track-bundled.jar
# SHA512
2002e27260b5cd4f96384828ef57f753916faab5ad06e0299958c3ab3e328045f2e805d0b1c3c56c85b4602d473c10d2c23d1098c94a4db93af0959c45b6ede8 dependency-track-apiserver.jar
262b582bd2dcbbb8966acd5dae3df88bc318590da0e66a7ac11f2197ccdca89b773013f317b5fe945650f16a48d2c4601356df10d77c10666d899917755cc0c8 dependency-track-bundled.jar
What's Changed
Bug Fixes 🐛
- Backport: Handle breaking change in Trivy server API by @nscuro in #3785
- Backport: Fix project name not showing in Jira tickets by @nscuro (original change by @lgrguricmileusnic) in #3787
- Backport: Add date format to support offset in NuGet timestamps by @nscuro (original change by @sahibamittal) in #3788
- Backport: Fix licenses not being resolved by name by @nscuro in #3786
- Backport: Fix Slack notifications failing when no base URL is configured by @nscuro in #3792
Dependency Updates 🤖
Other Changes
- Backport: Update database support docs by @nscuro in #3789
- Add changelog for v4.11.2 by @nscuro in #3790
Full Changelog: 4.11.1...4.11.2
4.11.1
For official releases, refer to Dependency Track Docs >> Changelogs for information about improvements and upgrade notes.
If additional details are required, consult the closed issues for this release milestone.
# SHA1
aa3d8ffc6b8f9d15a801148a93275ebeba922010 dependency-track-apiserver.jar
c57f1b8c003d95daa871096cbc37a6c03cd08907 dependency-track-bundled.jar
# SHA256
ed08e60e0761ced93454c14194da02be5950805911dbc7f7c611bdf0e753b437 dependency-track-apiserver.jar
e7613d6654083ab6e2c4ae24459444efe4d83df5d2c4d27e58a94bc809e2627a dependency-track-bundled.jar
# SHA512
75f4fcd203ccbbf494047b5866942b7a08fd1f97e98f40cd5aac57dd3401fcb2dc0e2e8953d54035dd3dd96e28c4df563ecee52df05769e8e530dc27e3e72f9b dependency-track-apiserver.jar
10e590eb849e1179688c787c3f52a5e333f20962c8f2ab4cec0b6a3f872991ff7d9f80748439bb33281e615c0bcd8ed65530abcc34f018f8b7f171c104e5caf5 dependency-track-bundled.jar
What's Changed
Bug Fixes 🐛
- Backport: Fix failing JSON BOM validation when
specVersion
is not one of the first fields by @nscuro in #3698 - Backport: Fix broken global vuln audit view for MSSQL by @nscuro in #3701
- Backport: fix os handling when trivy sets pkgType on properties by @nscuro (original change by @fnxpt) in #3729
Other Changes
Full Changelog: 4.11.0...4.11.1
4.11.0
For official releases, refer to Dependency Track Docs >> Changelogs for information about improvements and upgrade notes.
If additional details are required, consult the closed issues for this release milestone.
# SHA1
a9dae58a25c8aeeb54134ff054214505eb170db9 dependency-track-apiserver.jar
59b78c3f6b1979ba29c1bd754b7dc1005101fc49 dependency-track-bundled.jar
# SHA256
03160957fced99c3d923bbb5c6cb352740da1970bd4775b52bb451b95c4cefaf dependency-track-apiserver.jar
1a34808cd6c7a9bf7b181e4f175c077f1ee5d5a9daf327b330db9b1c63aac2d3 dependency-track-bundled.jar
# SHA512
79a34a20a93f57a1bde94fa876c03141c7696f177c560397ecf4fdd68da168419f3703eb0a4c7e40cb677536b15640f89dddb8f5e8cf32dda3115b8f6d5cf6b3 dependency-track-apiserver.jar
af25807596c617d2bdff437ba9fd4d2e8cdf28f220b8844d8ab3a53fe0510d65ac30167dbb752c22e5f96536362389099e5c4b25302e4adec84d48d6c4d15198 dependency-track-bundled.jar
What's Changed
Enhancements 🚀
- Return processing token when cloning project #2842 by @rkg-mm in #3260
- Hyades backport: Preprocess CWE dictionary by @nscuro in #3284
- Add "Show in Dependency-Graph" Button in "Affected Projects" List [improved version] by @rkg-mm in #3285
- Add "Show in Dependency-Graph" Button in "Affected Projects" List by @rbt-mm in #2942
- Update SPDX license list to v3.22 by @nscuro in #3368
- Store computed severities in the database by @nscuro in #3408
- feat(vulnerabilities): enhance API to support frontend changes for active/inactive affected projects by @setchy in #3425
- Subject prefix by @LaVibeX in #3422
- Trivy by @fnxpt in #3259
- Webhook alert token and new user alerts by @fnxpt in #3275
- Global Audit View: Vulnerabilities by @rbt-mm in #2472
- Refactor BOM upload processing for better efficiency, correctness, and consistency by @nscuro in #3357
- Bump CWE dictionary to v4.13 by @nscuro in #3491
- Apply consistent formatting to SQL queries; Use text blocks instead of string concatenation by @nscuro in #3492
- Align retry configuration and behavior across analyzers by @nscuro in #3494
- Add auto-generated changelog to GitHub releases by @nscuro in #3502
- Bump SPDX license list to v3.23 by @nscuro in #3508
- Validate uploaded BOMs against CycloneDX schema by @nscuro in #3522
- Add endpoint for updating API key comment by @nscuro in #3537
- OpenAPI spec fixes and improvements by @nscuro in #3557
- Disable automatic API key generation for teams. Fixes part of issue #2552. by @mprencipe in #3574
- Generate SARIF File Of Project Vulnerability Findings by @aravindparappil46 in #3561
- New feature: VulnDB Aliases! by @LaVibeX in #3588
- Implement the hackage and nixpkgs meta analyzers by @MangoIV in #3549
- Add support for component properties by @nscuro in #3499
- Leverage component properties for Trivy scans by @fnxpt in #3620
- Improve Lucene observability by @nscuro in #3535
- Include pagination parameters in OpenAPI spec by @nscuro in #3625
- Include sorting query parameters in OpenAPI spec by @nscuro in #3631
- support for experimental configurations by @fnxpt in #3621
- Gracefully handle unique constraint violations by @nscuro in #3648
- Add support for worker pool drain timeout by @nscuro in #3657
- Fall back to no authentication when OSS Index API token decryption fails by @nscuro in #3661
- Truncate
ComponentProperty
value at 1024 characters by @nscuro in #3662 - Add the project name and project URL to bom processing notifications by @2000rosser in #3666
- Bump bundled frontend to v4.11.0 by @nscuro in #3681
Bug Fixes 🐛
- Fix dropping of
CWE
table failing due to FK constraint by @nscuro in #3304 - Fix notifications not being sent for child projects where
active
isnull
by @nscuro in #3305 - Fix NPE in
VersionDistancePolicyEvaluator
when project has no direct dependencies by @nscuro in #3307 - Fix
ClassCastException
when updating an existingProjectMetadata#authors
field by @nscuro in #3311 - feat: Improve Error handling and add default version type by @jadyndev in #3313
- Fix NVD API's last modified timestamp requiring restart to be applied by @nscuro in #3322
- Project cloning logic for cloning policy violations and Violationanalysis by @mge-mm in #3248
- Ignore withdrawn Github advisories by @kepten in #3394
- Fix VulnDB parser being unable to import vulnerability records when 'nvd_additional_information' is empty by @lukas-braune in #3437
- Fix
URISyntaxException
when NPM PURL contains special characters by @nscuro in #3456 - Finding Attributed On date is not retained when cloning projects by @sebD in #3488
- adding cargo to IMetaAnalyzer by @leec94 in #3511
- Fix type of
purl
fields in Swagger docs by @sebD in #3512 - Perform License Resolution On Name Field During SBOM Import by @aravindparappil46 in #3555
- Update License Of Existing Components On BOM Upload by @aravindparappil46 in #3556
- Provide meaningful error message for
bom
andvex
exceeding Jackson's character limit by @nscuro in #3558 - Fix unhandled
NotFoundException
s causing aHTTP 500
response by @nscuro in #3559 - Extend length of
PURL
andPURLCOORDINATES
columns from 255 to 786 by @nscuro in #3560 - Validate UUID request parameters by @nscuro in #3590
- Vuln db severity by @LaVibeX in #3595
- Fix
JDOFatalUserException
for long reference URLs from OSS Index by @nscuro in #3650 - Catch all unhandled
ClientErrorException
s by @nscuro in #3659 - Fix unique constraint violation during NVD mirroring via feed files by @nscuro in #3664
- De-duplicate CPEs in NVD feed file parsing by @nscuro in #3667
- Fix missing default repos for Hackage and Nixpkgs by @nscuro in #3678
Dependency Updates 🤖
- Bump org.apache.httpcomponents.client5:httpclient5 from 5.2.1 to 5.3 by @dependabot in #3282
- Bump github/codeql-action from 2.22.8 to 2.22.9 by @dependabot in #3289
- Bump aquasecurity/trivy-action from 0.14.0 to 0.16.0 by @dependabot in #3288
- Bump com.google.cloud.sql:cloud-sql-connector-jdbc-sqlserver from 1.15.0 to 1.15.1 by @dependabot in #3298
- Bump io.github.jeremylong:open-vulnerability-clients from 5.1.0 to 5.1.1 by @dependabot in #3320
- Bump eclipse-temurin from
5f85d29
toe96937d
in /src/main/docker by @depen...
4.10.1
For official releases, refer to Dependency Track Docs >> Changelogs for information about improvements and upgrade notes.
If additional details are required, consult the closed issues for this release milestone.
# SHA1
1d728ce1788e5db8b3a9308338a9e7e8ab5af12e dependency-track-apiserver.jar
be32e1bc64d0b9b8019e340717d4ae3c12442ecd dependency-track-bundled.jar
# SHA256
e30731cd1915d3a1578cf5d8c8596d247fb11a82a3fe4c1ba2fb9fad01667aef dependency-track-apiserver.jar
ffa0ab6dc9be894d0887ca3e10c4ffe3a333305d98de940413fcdbb05e2bcebd dependency-track-bundled.jar
# SHA512
6c6d31ff9c7545225932af0f7315a37e657833717fb10be5402dc5f7c8db160d3c6482b290197238731d845d8e4ee8e4f215f5266314dd761d64396f7d6c42c7 dependency-track-apiserver.jar
00078670bd970beca99a7711a2afa7858ba9d4ee5c51adf4af0a9f5a025f16ac99ec8138f9fc9fd139caf428f6084a8107281f620a5f4a21161a5c1538b91fe7 dependency-track-bundled.jar
4.10.0
For official releases, refer to Dependency Track Docs >> Changelogs for information about improvements and upgrade notes.
If additional details are required, consult the closed issues for this release milestone.
# SHA1
c308b1f6a2d73fc2bba9da2cc33bf7e3ec49e851 dependency-track-apiserver.jar
b94fb9cbaa91c4e332bcec266e10a0f325f12e22 dependency-track-bundled.jar
# SHA256
d06f4550e16451ccb7843c36534172744934a7dc69e1d48e970a6eec24e49dc3 dependency-track-apiserver.jar
cf27db44e637b4bc551c16e659e81890f4c5d4f3b4ea9893ebf1717bff98b999 dependency-track-bundled.jar
# SHA512
4f190398de8084b1d481dc2e6ca3bb80afc675c96bba3dda1eaf1dc4faf8382c7a22f8be5953ed170dfc6765bd8a2efd67aa7d98826ce72c88e35cd16821f0f0 dependency-track-apiserver.jar
292f8af307adb3f52197ff1722e9565590f75a06a541fab2a54256dd2880a4abbf021cafdc43a112e7bf11364461bc5a26f90597b97d0190daf7365fcfd4efc5 dependency-track-bundled.jar
4.9.1
For official releases, refer to Dependency Track Docs >> Changelogs for information about improvements and upgrade notes.
If additional details are required, consult the closed issues for this release milestone.
# SHA1
99da5f705c3b0048ecf621e8c738a87147c693d9 dependency-track-apiserver.jar
487801d69bffb2e8def5aad9aa55c34be8cddcb2 dependency-track-bundled.jar
# SHA256
5d925f08f85fe7f39231357c4a4c8057fd354e048b7c9407efb20af78033ecec dependency-track-apiserver.jar
19ac4ede2932ff54c42e0466cdf7d5b410f7a44784562f237fc5b4b8891a8dc8 dependency-track-bundled.jar
# SHA512
59d37703aeef5376638d07ff544454c8660e0ba0c910bafac6998fb358a8b076063faacb4c4580617988b92a02872d409a3ccf3b2a89541cea2b452cda8f7ab1 dependency-track-apiserver.jar
c7c2c0cbcf3dd3d0fd94f7ca815f342d42818bed610217c7a6e4071b945340da393ed02b80ea6d58bb5da79a058f809b89820248a77b130750c64b3da0d09733 dependency-track-bundled.jar
4.9.0
For official releases, refer to Dependency Track Docs >> Changelogs for information about improvements and upgrade notes.
If additional details are required, consult the closed issues for this release milestone.
# SHA1
cd4ec4f1ed075f37476f46da11451158d7460502 dependency-track-apiserver.jar
6f3a077219fb49a502a88fcbb40e05865a23f5c5 dependency-track-bundled.jar
# SHA256
281f091107ef79d9b1e9361dc78608260b364eaa7dbbaeb29d4f7aef1a4bf67b dependency-track-apiserver.jar
4ca0b061ed83fa0b34ede8158f3ec0e2a7380c2736731995cf330f809076951f dependency-track-bundled.jar
# SHA512
b4368b1373438c0063b779631a40ec78e58ce0b82df4ca9e028a85c89777dd1b8fabbdf05d904552a45a70e79f6fff33bba1538f28529a07be556829c27ddea7 dependency-track-apiserver.jar
54e0d025744520b49b260b7dc37b7b4ad59771e24a7bed764ea2379063408326ef1fe42e67a22d3194d54fbf286f5eebfd69675463227ffc155e421955d5bb48 dependency-track-bundled.jar