github DependencyTrack/dependency-track 5.2.0

5 hours ago

Important

Please read the upgrade notes before upgrading your instance.

What's Changed

Enhancements 🚀

  • Make the Trivy API token optional by @arjavdongaonkar in #7178
  • Tweak apiserver Dockerfile by @nscuro in #7180
  • Make Dockerfile more layer cache friendly by @nscuro in #7181
  • Allow operators to load external JDBC drivers by @nscuro in #7182
  • Support inverted tag matching in policy scope by @arjavdongaonkar in #7176
  • Refactor component metrics computation to avoid pathological query plans by @nscuro in #7214
  • Add analyzer_identity in NEW_VULNERABILITY notifications by @sahibamittal in #7206
  • Fix N+1 queries in dependency graph endpoint by @nscuro in #7275
  • Improve efficiency of is_dependency_of and is_exclusive_dependency_of CEL functions by @nscuro in #7276
  • Avoid redundant component iteration during dependency graph export by @nscuro in #7277
  • Add checksum matching support for Snyk vuln analyzer by @mehab in #6835
  • Migrate cargo package metadata resolver to sparse index by @nscuro in #7315
  • Implement service accounts by @nscuro in #7293
  • Implement service account API key expiry by @nscuro in #7317
  • Sign webhook payloads with HMAC-SHA256 by @adilalperenciftci in #7323
  • Implement workload identity federation by @nscuro in #7330
  • Make the monitoring dashboards usable outside the dev stack by @nissessenap in #7335
  • Introduce outbound connection policy by @nscuro in #7449
  • Integrate outbound connection policy with shared HTTP client by @nscuro in #7450
  • Expose outbound connection policy to plugins by @nscuro in #7451
  • Streamline JDBI mappers by @nscuro in #7466
  • Support bracketed list strings in OIDC teams claim by @Akhil-1527 in #7467
  • Bump spdx license list 3.29.0 by @nscuro in #7502
  • Enforce a max size for BOM and VEX uploads by @nscuro in #7545
  • Batch finding bulk operations and notification emission by @nscuro in #7608

Bug Fixes 🐛

  • Run spotless:apply after Maven release plugin modifies them POM by @nscuro in #7138
  • v4-migrator: Reconcile PROJECT collection logic and tag by @arjavdongaonkar in #7172
  • v4-migrator: Dedup PROJECT_PROPERTY rows of collapsed projects by @arjavdongaonkar in #7171
  • Fix PURLs without version being submitted for analysis by @nscuro in #7196
  • Add option to use Snyk's per-package endpoint when batching is not available by @arjavdongaonkar in #7195
  • Remove unused LDAP properties by @nscuro in #7240
  • Fix management server preventing shutdown on initialization failures by @nscuro in #7278
  • Fix incorrect OpenAPI docs for POST /v1/project WRT parent semantics by @nscuro in #7312
  • Fix DATASOURCE_MIRRORING notifications not being emitted by @nscuro in #7313
  • Fix project lookup endpoints not serving aggregate metrics for collection projects by @nscuro in #7311
  • Resolve project parent before other fields in updateProject by @adityaanikam in #7262
  • Treat >=0 ranges as wildcard during vers matching by @nscuro in #7329
  • Fix broken link to VulnCheck token creation by @nscuro in #7347
  • Accumulate mirrored VulnerableSoftware by vulnerability key by @nscuro in #7351
  • Fix Checkmarx model conversion NPEs by @sahibamittal in #7352
  • Fix tag binding triggering unnecessary relationship loads by @nscuro in #7353
  • Fix OS package scanning for Trivy analyzer by @nscuro in #7355
  • Prevent NPEs during DataNucleus L1 cache eviction by @nscuro in #7357
  • Fix proxy authentication for GitHub Advisories vuln data source by @nscuro in #7356
  • Fix calculated CVSSv4 score only considering base metrics by @nscuro in #7358
  • Fix NVD vuln data source iteration and watermarking issues by @nscuro in #7359
  • Move vuln data source mirroring off JDO by @nscuro in #7382
  • Fix lack of context in NVD & OSV unexpected status code exception messages by @nscuro in #7385
  • Fix invalid PURLs causing list API endpoints to fail by @nscuro in #7501
  • Fix failure to match CPE with wildcard version and version range >=0 by @nscuro in #7514
  • Fix internal vulns with finding attributions failing deletion by @nscuro in #7542
  • PEP 503-normalize PyPI package names for vuln matching by @nscuro in #7546
  • Treat NuGet package names as case-insensitive for vuln matching by @nscuro in #7547
  • Fix manually assigned findings being deactivated on analysis by @nscuro in #7551
  • Fix Trivy findings dropped for PURLs with URL-valued qualifiers by @nissessenap in #7581
  • Consistently tolerate trailing slashes in configurable URLs by @nscuro in #7607
  • Fix collection project metrics shape when children have no metrics by @nscuro in #7609
  • Fix missing pagination in /v1/vulnerability/component/{uuid} by @nscuro in #7610

Dependency Updates 🤖

  • Update maintenance branch in Dependabot config to 5.1.x by @nscuro in #7139
  • chore(deps): Bump io.smallrye.config:smallrye-config-bom from 3.18.1 to 3.18.2 by @dependabot[bot] in #7143
  • Bump squawk to 2.63.0 by @nscuro in #7150
  • Pin spectral image by @nscuro in #7151
  • Group CodeQL actions in Dependabot by @nscuro in #7156
  • chore(deps): Bump the codeql group with 2 updates by @dependabot[bot] in #7157
  • Bump com.uber.nullaway:nullaway from 0.13.8 to 0.14.0 by @dependabot[bot] in #7167
  • Bump com.adobe.testing:s3mock-testcontainers from 5.1.0 to 5.2.0 by @dependabot[bot] in #7185
  • Bump com.icegreen:greenmail-junit5 from 2.1.12 to 2.1.13 by @dependabot[bot] in #7184
  • Bump actions/setup-java from 5.7.0 to 6.0.0 by @dependabot[bot] in #7183
  • Bump org.openapitools:openapi-generator-maven-plugin from 7.24.0 to 7.25.0 by @dependabot[bot] in #7198
  • Bump io.dropwizard.flywaydb:flyway-bom from 13.3.0 to 13.4.0 by @dependabot[bot] in #7215
  • Bump com.diffplug.spotless:spotless-maven-plugin from 3.10.0 to 3.10.1 by @dependabot[bot] in #7217
  • Bump org.apache.felix:maven-bundle-plugin from 6.1.0 to 6.1.2 by @dependabot[bot] in #7216
  • Bump the codeql group with 2 updates by @dependabot[bot] in #7227
  • Bump zizmorcore/zizmor-action from 0.6.2 to 0.6.3 by @dependabot[bot] in #7228
  • Bump oasdiff/oasdiff-action/breaking from 0.1.13 to 0.1.14 by @dependabot[bot] in #7229
  • Bump com.github.luben:zstd-jni from 1.5.7-15 to 1.5.7-16 by @dependabot[bot] in #7230
  • Bump org.apache.maven.plugins:maven-compiler-plugin from 3.15.0 to 3.16.0 by @dependabot[bot] in #7231
  • Bump com.uber.nullaway:nullaway from 0.14.0 to 0.14.1 by @dependabot[bot] in #7232
  • Bump lib.protobuf-java.version from 4.36.0 to 4.36.1 by @dependabot[bot] in #7245
  • Bump org.apache.maven.plugins:maven-surefire-plugin from 3.5.6 to 3.6.0 by @dependabot[bot] in #7248
  • Bump org.apache.maven.plugins:maven-surefire-report-plugin from 3.5.6 to 3.6.0 by @dependabot[bot] in #7249
  • Bump io.swagger.parser.v3:swagger-parser from 2.1.47 to 2.1.48 by @dependabot[bot] in #7247
  • Bump lib.swagger.version from 2.2.54 to 2.2.55 by @dependabot[bot] in #7266
  • Bump org.apache.maven.plugins:maven-failsafe-plugin from 3.5.6 to 3.6.0 by @dependabot[bot] in #7267
  • Bump lib.byte-buddy.version from 1.18.12 to 1.18.13 by @dependabot[bot] in #7274
  • Bump org.metaeffekt.core:ae-security from 0.156.6 to 0.157.0 by @dependabot[bot] in #7281
  • Bump lib.jetty.version from 12.1.12 to 12.1.13 by @dependabot[bot] in #7282
  • Bump oasdiff/oasdiff-action/breaking from 0.1.14 to 0.1.15 by @dependabot[bot] in #7295
  • Bump docker/setup-qemu-action from 4.2.0 to 4.3.0 by @dependabot[bot] in #7296
  • Bump org.slf4j:slf4j-bom from 2.0.18 to 2.0.19 by @dependabot[bot] in #7298
  • Bump com.diffplug.spotless:spotless-maven-plugin from 3.10.1 to 3.10.2 by @dependabot[bot] in #7297
  • Bump io.dropwizard.flywaydb:flyway-bom from 13.4.0 to 13.5.0 by @dependabot[bot] in #7300
  • chore(deps): Bump io.github.openfeign:feign-bom from 13.13 to 13.14 by @dependabot[bot] in #7134
  • Bump org.jetbrains.kotlin:kotlin-bom from 2.4.10 to 2.4.20 by @dependabot[bot] in #7319
  • Bump io.github.openfeign:feign-bom from 13.14 to 13.15 by @dependabot[bot] in #7324
  • Bump com.microsoft.sqlserver:mssql-jdbc from 13.4.0.jre11 to 13.6.0.jre11 by @dependabot[bot] in #7341
  • Bump alpine base image to 3.24.2 by @nscuro in #7380
  • Bump the codeql group with 2 updates by @dependabot[bot] in #7388
  • Bump zizmorcore/zizmor-action from 0.6.3 to 0.6.4 by @dependabot[bot] in #7389
  • Bump oasdiff/oasdiff-action/breaking from 0.1.15 to 0.1.16 by @dependabot[bot] in #7390
  • Bump actions/setup-java from 6.0.0 to 6.0.1 by @dependabot[bot] in #7391
  • Bump com.adobe.testing:s3mock-testcontainers from 5.2.0 to 5.2.2 by @dependabot[bot] in #7392
  • Bump io.dropwizard.flywaydb:flyway-bom from 13.5.0 to 13.6.0 by @dependabot[bot] in #7393
  • Bump io.github.jeremylong:open-vulnerability-clients from 9.0.6 to 9.0.7 by @dependabot[bot] in #7394
  • Bump io.smallrye.config:smallrye-config-bom from 3.18.2 to 3.18.3 by @dependabot[bot] in #7395
  • Bump org.apache.felix:maven-bundle-plugin from 6.1.2 to 6.2.0 by @dependabot[bot] in #7396
  • Bump io.github.nscuro:versatile-core from 0.24.0 to 0.25.0 by @dependabot[bot] in #7411
  • Bump org.codehaus.mojo:exec-maven-plugin from 3.6.3 to 3.6.4 by @dependabot[bot] in #7412
  • Bump io.github.ascopes:protobuf-maven-plugin from 5.1.8 to 5.1.9 by @dependabot[bot] in #7413
  • Bump org.apache.maven.plugins:maven-install-plugin from 3.1.4 to 3.2.0 by @dependabot[bot] in #7414
  • Bump lib.byte-buddy.version from 1.18.13 to 1.18.14 by @dependabot[bot] in #7415
  • Bump io.prometheus:prometheus-metrics-bom from 1.8.0 to 1.9.0 by @dependabot[bot] in #7424
  • Bump org.apache.maven.plugins:maven-deploy-plugin from 3.1.4 to 3.2.0 by @dependabot[bot] in #7425
  • Bump org.metaeffekt.core:ae-security from 0.157.0 to 0.157.1 by @dependabot[bot] in #7426
  • Bump org.codehaus.mojo:build-helper-maven-plugin from 3.6.1 to 3.6.2 by @dependabot[bot] in #7428
  • Bump io.dropwizard.flywaydb:flyway-bom from 13.6.0 to 13.7.0 by @dependabot[bot] in #7438
  • Bump com.github.luben:zstd-jni from 1.5.7-16 to 1.5.7-17 by @dependabot[bot] in #7437
  • Bump io.smallrye.config:smallrye-config-bom from 3.18.3 to 4.0.0 by @dependabot[bot] in #7455
  • Bump lib.protobuf-java.version from 4.36.1 to 4.36.2 by @dependabot[bot] in #7454
  • Bump the codeql group with 2 updates by @dependabot[bot] in #7469
  • Bump docker/build-push-action from 7.3.0 to 7.4.0 by @dependabot[bot] in #7470
  • Bump docker/setup-qemu-action from 4.3.0 to 4.4.0 by @dependabot[bot] in #7471
  • Bump oasdiff/oasdiff-action/breaking from 0.1.16 to 0.1.17 by @dependabot[bot] in #7472
  • Bump docker/setup-buildx-action from 4.3.0 to 4.4.1 by @dependabot[bot] in #7473
  • Bump com.adobe.testing:s3mock-testcontainers from 5.2.2 to 5.2.3 by @dependabot[bot] in #7474
  • Bump com.github.luben:zstd-jni from 1.5.7-17 to 1.5.7-18 by @dependabot[bot] in #7477
  • Bump com.github.ben-manes.caffeine:caffeine from 3.2.4 to 3.3.0 by @dependabot[bot] in #7478
  • Bump io.github.ascopes:protobuf-maven-plugin from 5.1.9 to 5.1.10 by @dependabot[bot] in #7479
  • Bump com.icegreen:greenmail-junit5 from 2.1.13 to 2.1.14 by @dependabot[bot] in #7482
  • Bump tools.jackson:jackson-bom from 3.2.2 to 3.2.3 by @dependabot[bot] in #7504
  • Bump org.eclipse.microprofile.config:microprofile-config-api from 3.1.1 to 3.1.2 by @dependabot[bot] in #7506
  • Bump com.fasterxml.jackson:jackson-bom from 2.22.2 to 2.22.3 by @dependabot[bot] in #7505
  • Bump versatile to 0.26.0 by @nscuro in #7515
  • Bump org.slf4j:slf4j-nop from 1.7.36 to 2.0.20 by @dependabot[bot] in #7518
  • Bump com.github.luben:zstd-jni from 1.5.7-18 to 1.5.7-19 by @dependabot[bot] in #7521
  • Bump org.slf4j:slf4j-bom from 2.0.19 to 2.0.20 by @dependabot[bot] in #7522
  • Bump org.mockito:mockito-bom from 5.23.0 to 5.24.0 by @dependabot[bot] in #7530
  • Bump org.metaeffekt.core:ae-security from 0.157.1 to 0.157.2 by @dependabot[bot] in #7528
  • Bump lib.logback.version from 1.6.3 to 1.6.4 by @dependabot[bot] in #7534
  • Bump io.dropwizard.flywaydb:flyway-bom from 13.7.0 to 13.8.0 by @dependabot[bot] in #7535
  • Bump com.github.luben:zstd-jni from 1.5.7-19 to 1.5.7-20 by @dependabot[bot] in #7537
  • Bump com.uber.nullaway:nullaway from 0.14.1 to 0.14.2 by @dependabot[bot] in #7536
  • Bump the codeql group with 2 updates by @dependabot[bot] in #7567
  • Bump com.diffplug.spotless:spotless-maven-plugin from 3.10.2 to 3.10.3 by @dependabot[bot] in #7568
  • Bump org.apache.commons:commons-lang3 from 3.20.0 to 3.21.0 by @dependabot[bot] in #7573
  • Bump com.tngtech.archunit:archunit-junit5 from 1.5.0 to 1.5.1 by @dependabot[bot] in #7569
  • Bump org.jdbi:jdbi3-bom from 3.54.0 to 3.55.0 by @dependabot[bot] in #7571
  • Bump eclipse-temurin from 25.0.4_7-jdk-alpine to 25.0.4.1_1-jdk-alpine in /apiserver/src/main/docker by @dependabot[bot] in #7588
  • Bump com.fasterxml.woodstox:woodstox-core from 7.2.2 to 7.3.0 by @dependabot[bot] in #7600
  • Bump com.google.guava:guava from 33.7.1-jre to 33.7.2-jre by @dependabot[bot] in #7612
  • Bump io.github.ascopes:protobuf-maven-plugin from 5.1.10 to 5.1.11 by @dependabot[bot] in #7620
  • Bump lib.logback.version from 1.6.4 to 1.6.5 by @dependabot[bot] in #7619

Documentation 📃

  • Update repository docs by @nscuro in #7162
  • Add ADR for policy violation messages by @fffinkel in #7322
  • Make description of Snyk's checksumMatchingEnabled less verbose by @nscuro in #7606
  • Tweak docs of allowed destinations property by @nscuro in #7611

Other Changes

  • Decouple API v1 DELETE endpoints from JDO models by @nscuro in #7148
  • Decouple more API v1 endpoints from JDO models by @nscuro in #7149
  • Fix broken clean-build-cache make target by @nscuro in #7160
  • Remove JDO from auth path by @nscuro in #7168
  • Switch Alpine tests to Postgres and remove H2 by @nscuro in #7169
  • Address zizmor findings by @nscuro in #7193
  • Remove ServiceRegistry from plugin API by @nscuro in #7255
  • Relocate analyzer_identity notification field by @nscuro in #7279
  • Dogfood API v2 OpenAPI spec for e2e tests by @nscuro in #7287
  • Reduce noise of e2e test log output by @nscuro in #7288
  • Drop deprecated AFFECTEDVERSIONATTRIBUTION.LAST_SEEN column by @nscuro in #7349
  • Cleanup dead code by @nscuro in #7383
  • Enable default ERROR-level ErrorProne checks and fix issues by @nscuro in #7457
  • Improve effectiveness of caching in CI by @nscuro in #7458
  • Promote various Error Prone checks to ERROR by @nscuro in #7459
  • Expand CompileTimeConstant annotation usage by @nscuro in #7460
  • Enable JDBI to interface with JDO transactions by @nscuro in #7461
  • Remove duplicated or unused JDO cruft by @nscuro in #7462
  • Migrate config property reads from JDO to JDBI by @nscuro in #7463
  • Remove redundant JDO VulnerableSoftware sync logic by @nscuro in #7464
  • Migrate more code from JDO to JDBI by @nscuro in #7465
  • Co-locate persistence code with its feature packages by @nscuro in #7498
  • Disable caching in docker/setup-qemu-action by @nscuro in #7525
  • Add regression test for Go pseudo version range matching by @nscuro in #7548
  • Add shell script for backport skill by @nscuro in #7549
  • Ignore major version bumps of eclipse-temurin image by @nscuro in #7587

New Contributors

Full Changelog: 5.1.0...5.2.0

Don't miss a new dependency-track release

NewReleases is sending notifications on new releases.