github DependencyTrack/dependency-track 4.13.4

10 days ago

For official releases, refer to Dependency Track Docs >> Changelogs for information about improvements and upgrade notes.
If additional details are required, consult the closed issues for this release milestone.

# SHA1
048b46829358cfde1f4d90b9298984224c75f6ae  dependency-track-apiserver.jar
b3eb198254783462dc7d147791537fa50b11483e  dependency-track-bundled.jar
# SHA256
2ca674108a08bf71642ddec6704125fae720161c4c40268fd19557e8b116d9d0  dependency-track-apiserver.jar
a8252f66f9b3c9253553e1d2a40fb0169f90c31895e36f57bc5992068ff473f5  dependency-track-bundled.jar
# SHA512
25d697390a5a0316b85b67e01f29caaeba8cec955318a7ecd762189aefad0175bf338228361790796b153e53953c663cd05dca940d51dc4a30d015fb897a1c47  dependency-track-apiserver.jar
698f3f8ddc9958c7bd17f17e66c3b79d04181b509bd8fd42f01ee58aeb23cf5a88b208bcc13b6815c7d5396b049881c830aee1810420ae09923fbef766cf33ea  dependency-track-bundled.jar

What's Changed

Enhancements 🚀

  • Backport: Migrate to NVD 2.0 data feeds by @nscuro in #5236

Bug Fixes 🐛

  • Backport: Handle URLs in composer package metadata pattern by @nscuro in #5234
  • Backport: Fix failing TrivyAnalysisTaskIntegrationTest by @nscuro in #5241
  • Backport: Fix inconsistent ordering in findings endpoints by @nscuro in #5247
  • Handle adduser / addgroup removal in Debian base image by @nscuro in #5246
  • Backport: Fix failing Trivy OS matching for distro versions with special characters by @nscuro in #5249

Dependency Updates 🤖

Other Changes

Full Changelog: 4.13.3...4.13.4

Don't miss a new dependency-track release

NewReleases is sending notifications on new releases.